Skip to content

fix(transport): target resource update notifications - #101

Merged
ContextVM-org merged 7 commits into
ContextVM:masterfrom
Anand-0037:fix/issue-52-resource-update-subscriptions
Sep 24, 2026
Merged

ContextVM-org merged 7 commits into
ContextVM:masterfrom
Anand-0037:fix/issue-52-resource-update-subscriptions

Conversation

@Anand-0037

@Anand-0037 Anand-0037 commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Fixes notifications/resources/updated delivery so resource updates are sent only to subscribed clients instead of all initialized sessions. Servers can define which update URIs are sub-resources of a subscribed URI; exact URI matching works by default.

Changes

  • Add a dedicated bidirectional SubscriptionStore.
  • Track authorized resources/subscribe and resources/unsubscribe requests without tying subscriptions to response correlation.
  • Route resource updates to exact URI subscribers and, when configured, subscribers matched by the server's matchesSubResource callback. Deduplicate clients matching both.
  • Drop malformed, unknown, and no-subscriber updates instead of falling through to generic broadcast.
  • Remove subscriptions on session eviction, including probe-timeout removal, and clear them when the transport closes.
  • Keep existing list-change, logging, progress, and targeted sendNotification behavior unchanged.

Subscriptions intentionally do not veto session eviction, and stale entries from an application-rejected subscribe are tolerated as discussed in #52.

Tests

  • Subscription store and broadcaster coverage for exact matching, server-defined parent/child matching, unrelated URIs, deduplication, and unsubscribe.
  • Two-client relay regression coverage, including parent/child delivery and unsubscribe.
  • Focused resource-update tests: 15 passed, 0 failed. The probe-timeout/reconnect regression also passed locally.
  • Local lint, typecheck, build, verify-exports, publint, formatting, and git diff --check passed.
  • GitHub Actions for d43ae78 are awaiting maintainer approval.

Closes #52

@Anand-0037
Anand-0037 force-pushed the fix/issue-52-resource-update-subscriptions branch from eed4e06 to f2146be Compare September 20, 2026 11:52
@1amKhush

Copy link
Copy Markdown
Contributor

@Anand-0037 subscriptions survive a probe-timeout session removal. The new cleanup runs in the LRU eviction callback, but a stream probe timeout removes the session directly, bypassing that callback. I reproduced a removed session whose URI still lists the client as a subscriber. If that pubkey establishes a new session, it can receive resource updates without subscribing again. I think you should clear subscriptions on this removal path and add a timeout/reconnect test.

@Anand-0037

Copy link
Copy Markdown
Contributor Author

Thanks, I missed the direct session removal in the probe-timeout path. I've cleared subscriptions there and added a regression for reconnecting with the same key; resource updates are no longer delivered until the client subscribes again.

@1amKhush

Copy link
Copy Markdown
Contributor

@Anand-0037 Parent resource subscriptions miss valid sub-resource updates. The broadcaster performs an exact URI lookup, but MCP allows an update URI to identify a sub-resource of the subscribed URI. See the official MCP schema.

I reproduced this case:

  • Client subscribes to resource://repo
  • Server updates resource://repo/child
  • No notification is delivered because only getSubscribers('resource://repo/child') is checked
    The implementation needs a way to resolve server-defined parent/sub-resource relationships and a regression test for this case.

I recommend fixing the finding before merge.

@Anand-0037

Copy link
Copy Markdown
Contributor Author

@1amKhush Fixed in d43ae78. I added optional server-defined sub-resource matching while keeping exact URI matching as the default, with regression coverage for parent/child delivery, unrelated URIs, deduplication, and unsubscribe. The new GitHub Actions runs are awaiting maintainer approval.

@1amKhush

Copy link
Copy Markdown
Contributor

@ContextVM-org Lgtm for merge

…ests

Maintainer follow-up on review of ContextVM#101 (issue ContextVM#52):

- Record resources/subscribe and resources/unsubscribe only after the
  request is actually forwarded to the MCP server (dispatch terminal).
  A middleware-swallowed or failed request no longer leaves phantom
  subscription state behind, and a dropped unsubscribe can no longer
  re-add a subscription that never existed.
- Clear a client's subscriptions when authorization rejects it, so a
  revoked client stops receiving resource updates immediately instead
  of lingering until session eviction.
- Regression tests for both paths and a changeset note.

Also merges master (ContextVM#102 probe-timeout teardown fix) into the branch so
the probe-timeout regression runs against the current writer code.
@ContextVM-org
ContextVM-org merged commit 1408288 into ContextVM:master Sep 24, 2026
@Anand-0037
Anand-0037 deleted the fix/issue-52-resource-update-subscriptions branch September 24, 2026 14:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

notifications/resources/updated is not correlated and is broadcast to all initialized sessions

3 participants