Skip to content

docs(security): update SECURITY.md for MCP 2026-07-28 stateless capability model (#131) - #136

Merged
CryptoJones merged 2 commits into
mainfrom
docs/issue-131-security-stateless-model
Oct 7, 2026
Merged

CryptoJones merged 2 commits into
mainfrom
docs/issue-131-security-stateless-model

Conversation

@CryptoJones

Copy link
Copy Markdown
Owner

Description

Resolves #131.

In commit daa358a (#104), the server adopted MCP revision 2026-07-28 via the mcp 2.x SDK. This revision made the MCP transport stateless and removed client sessions. In src/perplexity_agent/server.py, stored state is addressed using shared namespaces (_STORE_NAMESPACE = "shared"), where possession of the unguessable response ID or random capability token (retrieve_key) provides authorization.

This PR:

  1. Updates SECURITY.md:
    • Replaces stale descriptions of legacy session-scoping with accurate documentation of the stateless capability-handle model.
    • Clarifies authorization mechanics for both SQLite response snapshots (response_id) and in-memory offloaded tool results (retrieve_key).
    • Updates the NSA recommendation control mapping to reference MCPServer.
  2. Updates BACKLOG.md:
  3. Updates SemVer:
    • Bumps version from 0.3.1 to 0.4.0 in pyproject.toml, src/perplexity_agent/__init__.py, and uv.lock.
    • Adds release notes and comparison links for [0.4.0] in CHANGELOG.md.

Verification

  • uv run pytest: 201 passed
  • uv run ruff check .: clean
  • uv run mypy src: clean (17 source files)
  • uv lock --check: clean

@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 7f6bce77-efbc-4f35-b476-b0274b7a7915
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@CryptoJones
CryptoJones merged commit 63a0c42 into main Oct 7, 2026
24 of 31 checks passed
@CryptoJones
CryptoJones deleted the docs/issue-131-security-stateless-model branch October 7, 2026 03:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Docs: Update SECURITY.md to reflect MCP 2026-07-28 stateless capability model

1 participant