You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Scope. Per-session bookkeeping for active MCP sessions, plus the two listChanged notification flows: notifications/tools/list_changed when a role mutates and notifications/resources/list_changed when the schema mutates.
Design reference. Section "tools/list_changed session bookkeeping" in #465.
Acceptance criteria
In-memory session table keyed by Mcp-Session-Id: { user, role, profile, sseStream? }. Idle sessions terminated per mcp.session.idleTimeoutSeconds.
Subscribe to Harper's existing role-cache-invalidation events (security/user.ts); on event, recompute tools/list for affected sessions, diff against the cached list, send notifications/tools/list_changed over each session's SSE channel.
Subscribe to Harper's existing schema-reload events (create_schema / create_table / drop_table / GraphQL reload); on event, recompute resources/list for affected sessions and send notifications/resources/list_changed.
Never broadcast. Notifications are computed per-session so users never learn about schema/role changes for objects they cannot see.
Unit + integration tests: open two sessions with different roles; mutate one role; verify only the affected session receives notifications/tools/list_changed.
Out of scope. Resumability via Last-Event-ID (v2). resources/subscribe (v2). Cross-process session sharing (v2).
Stacks on.#615, #616, #617, #618 (needs both profiles' tool lists and the resources capability).
# Open SSE on session A; alter_role for the user attached to session A in another session B.# Expected: SSE event "notifications/tools/list_changed" arrives on session A's GET /mcp stream.# Session A's next tools/list returns the new filtered set.
Landed in PR #856 (consolidated PR-1 feat/mcp-tools) — bundled with #617, #618, #619, #620, #622 per @kriszyp's review-load preference. See umbrella #465 for the full delivery table.
Scope. Per-session bookkeeping for active MCP sessions, plus the two listChanged notification flows:
notifications/tools/list_changedwhen a role mutates andnotifications/resources/list_changedwhen the schema mutates.Design reference. Section "
tools/list_changedsession bookkeeping" in #465.Acceptance criteria
Mcp-Session-Id:{ user, role, profile, sseStream? }. Idle sessions terminated permcp.session.idleTimeoutSeconds.security/user.ts); on event, recomputetools/listfor affected sessions, diff against the cached list, sendnotifications/tools/list_changedover each session's SSE channel.create_schema/create_table/drop_table/ GraphQL reload); on event, recomputeresources/listfor affected sessions and sendnotifications/resources/list_changed.notifications/tools/list_changed.Out of scope. Resumability via
Last-Event-ID(v2).resources/subscribe(v2). Cross-process session sharing (v2).Stacks on. #615, #616, #617, #618 (needs both profiles' tool lists and the resources capability).
Branch & PR conventions
feat/mcp-listchanged-sessionsmain(after dependencies merge).Smoke test
Tracking. Part of #465. Sub-issue #7 of 11.