Skip to content

fix(mcp): warn when stateless session middleware never attached - #856

Draft
posthog[bot] wants to merge 1 commit into
mainfrom
posthog-self-driving/fixmcp-warn-when-stateless-session-d1e090
Draft

fix(mcp): warn when stateless session middleware never attached#856
posthog[bot] wants to merge 1 commit into
mainfrom
posthog-self-driving/fixmcp-warn-when-stateless-session-d1e090

Conversation

@posthog

@posthogposthogBot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

💡 Motivation and Context

  • A customer on an older MCP spec lost weeks of analytics sessions because PostHogMcpStatelessSessionMiddlewaresilently never attached — and nothing in the SDK said so. It cost two support round trips and a full SDK release that didn't fix their issue.
  • The mint is zero-config only for an ASGI app built afterinstrument() runs. autowire_stateless_mint monkey-patches the app factories on the server, so an app built or mounted beforeinstrument() (the common FastAPI-mounts-at-import case) gets no middleware at all.
  • The failure was completely dark: wiring errors were swallowed into a log line, and a missing session just fell through resolve_session_id to the per-process generated branch. Classic works-in-dev (mcp.run() calls the patched factory), dark-in-prod (FastAPI mounts its own app).
  • This is a wiring problem, not the separate MCP 2026-07-28 spec break — that one is covered by draft PR feat(mcp): support the MCP 2026-07-28 spec and mcp 2.x SDK #830. This PR is additive to feat(mcp): support the MCP 2026-07-28 spec and mcp 2.x SDK #830 and touches asgi.py (which feat(mcp): support the MCP 2026-07-28 spec and mcp 2.x SDK #830 does not); the only shared file is session.py, which this PR deliberately leaves untouched to avoid conflict.

💚 How did you test it?

Added unit + end-to-end tests, and reproduced the customer's ordering trap against a real stateless FastMCP streamable-HTTP transport.

  • Runtime signal, warn-once — HTTP request, no token, no Mcp-Session-Idgenerated session fires exactly one warning; repeat requests stay quiet.
  • No false positives — stdio (no HTTP request) and a correctly-wired server that replays our token both stay silent.
  • instrument-time signal — building streamable_http_app() before instrument() triggers the warning.
  • Reproduced end-to-end: with the app built before instrument(), a tools/call with no session header fires both warnings; the correctly-ordered path fires neither.
  • Full MCP suite: 147 passed, 1 skipped. ruff check / ruff format clean.

Two independent signals now surface the failure (either would have ended the ticket on day one):

SignalWhenPoints to
instrument() warningstreamable_http_app() was already called before instrument() ranmanual add_middleware + posthog/mcp/README.md
Runtime warn-oncefirst HTTP tool call resolves with no session on a stateless serversame

Docs: the manual app.add_middleware(PostHogMcpStatelessSessionMiddleware) path now lives in a findable posthog/mcp/README.md, plus a sharpened note in examples/mcp_stateless.py.

📝 Checklist

  • I reviewed the submitted code.
  • I added tests to verify the changes.
  • I updated the docs if needed.
  • No breaking change or entry added to the changelog.

If releasing new changes

  • Ran sampo add to generate a changeset file

🤖 Agent context

Autonomy: Fully autonomous

  • Authored by Claude Code (Opus 4.8) driving the PostHog self-driving harness, from an inbox report.
  • Root-caused the silent failure to autowire only affecting factories consumed after instrument(). Chose two complementary detectors: an instrument-time probe of FastMCP's lazily-created _session_manager (set once streamable_http_app() has run) and a runtime warn-once gated on http_request AND no token AND no mcp_session_id AND session_source == "generated" — the precise fingerprint that can't fire for stdio or correctly-wired servers.
  • Deliberately did not touch posthog/mcp/session.py so this stays conflict-free with draft feat(mcp): support the MCP 2026-07-28 spec and mcp 2.x SDK #830; plumbed a new http_request flag through prepare_request and the adapters instead.

Created with PostHog Desktop from this inbox report.

The stateless-session mint (PostHogMcpStatelessSessionMiddleware) is
zero-config only when the ASGI app is built after instrument() runs.
An app built or mounted earlier (the common FastAPI case) silently gets
no middleware, so every session falls back to a fragmented per-process
id with nothing in the SDK saying so.
Make the failure loud with two independent signals:
- instrument() warns when streamable_http_app() was already called
before it ran (FastMCP's cached _session_manager is the tell).
- A one-time runtime warning fires when a tool call arrives over HTTP
with no session id and resolution falls back to a generated session.
Both point to the manual fix, app.add_middleware(...), now documented
in posthog/mcp/README.md. No behavior change on correctly-wired servers
or on stdio.
Generated-By: PostHog Code
Task-Id: 9efb38cb-2672-4236-8da6-208e4f83f686
@github-actions

github-actionsBot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

posthog-python Compliance Report

Date: 2026-08-07 13:25:20 UTC
Duration: 256384ms

✅ All Tests Passed!

111/111 tests passed


Capture_V1 Tests

94/94 tests passed

View Details
TestStatusDuration
Endpoint And Method.Targets V1 Endpoint516ms
Endpoint And Method.Does Not Use Legacy Endpoints510ms
Required Headers.Has Authorization Bearer Header510ms
Required Headers.Has Content Type Json510ms
Required Headers.Has Posthog Sdk Info Format511ms
Required Headers.Has Posthog Attempt Header510ms
Required Headers.Has Posthog Request Id510ms
Required Headers.Has Posthog Request Timestamp510ms
Required Headers.Has User Agent510ms
Body Format.Body Has Created At And Batch510ms
Body Format.No Api Key In Body510ms
Body Format.No Sent At In Body510ms
Event Format.Event Has Required Root Fields511ms
Event Format.Event Uuid Is Valid510ms
Event Format.Event Timestamp Is Rfc3339510ms
Event Format.Distinct Id Is String510ms
Event Format.Distinct Id At Root Not Properties511ms
Event Format.Custom Properties Preserved510ms
Event Format.Set Properties Preserved510ms
Event Format.Set Once Properties Preserved511ms
Event Format.Groups Properties Preserved511ms
Event Format.Sdk Generates Uuid If Not Provided510ms
Event Format.Event Has Required Root Fields Batch514ms
Event Format.Event Uuid Is Valid Batch514ms
Event Format.Event Timestamp Is Rfc3339 Batch513ms
Event Format.Distinct Id Is String Batch514ms
Event Format.Distinct Id At Root Not Properties Batch514ms
Event Format.Custom Properties Preserved Batch513ms
Event Format.Set Properties Preserved Batch514ms
Event Format.Set Once Properties Preserved Batch513ms
Event Format.Groups Properties Preserved Batch514ms
Event Format.Sdk Generates Uuid If Not Provided Batch514ms
Batch Behavior.Multiple Events In Single Batch518ms
Batch Behavior.Batch Envelope Smoke516ms
Batch Behavior.Flush With No Events Sends Nothing506ms
Batch Behavior.Flush At Triggers Batch1011ms
Batch Behavior.Created At Reflects Batch Creation Time511ms
Deduplication.Generates Unique Uuids518ms
Deduplication.Different Events Same Content Different Uuids512ms
Deduplication.Preserves Uuid On Retry6519ms
Deduplication.Preserves Timestamp On Retry6519ms
Deduplication.Preserves Uuid And Timestamp On Batch Retry6519ms
Deduplication.No Duplicate Events In Batch518ms
Header Behavior On Retry.Attempt Header Starts At One510ms
Header Behavior On Retry.Attempt Header Increments On Retry13524ms
Header Behavior On Retry.Request Id Preserved On Retry6520ms
Header Behavior On Retry.Different Requests Have Different Request Ids3020ms
Header Behavior On Retry.Request Timestamp Changes On Retry6520ms
Response Format Validation.Success Response Has Uuid Keyed Results511ms
Response Format Validation.Success Response Has Ok For Each Event514ms
Response Format Validation.Success No Retry After When All Ok513ms
Response Format Validation.Success Retry After Present When Retry Events1515ms
Response Format Validation.Success No Retry After When Drop Only513ms
Response Format Validation.Response Echoes Request Id510ms
Retry Behavior.Retries On 4086518ms
Retry Behavior.Retries On 5006520ms
Retry Behavior.Retries On 5038523ms
Retry Behavior.Retries On 5046519ms
Retry Behavior.Retryable Errors Have Retry After3518ms
Retry Behavior.Respects Retry After On Retryable Error11516ms
Retry Behavior.Does Not Retry On 4002512ms
Retry Behavior.Does Not Retry On 4012513ms
Retry Behavior.Does Not Retry On 4022513ms
Retry Behavior.Does Not Retry On 4132513ms
Retry Behavior.Does Not Retry On 4152514ms
Retry Behavior.Non Retryable Errors Have No Retry After2513ms
Retry Behavior.Implements Backoff22528ms
Retry Behavior.Max Retries Respected22526ms
Partial Batch Handling.Handles 200 Full Success2512ms
Partial Batch Handling.Handles 200 With All Ok3518ms
Partial Batch Handling.Does Not Retry Dropped Events3516ms
Partial Batch Handling.Does Not Retry Limited Events3516ms
Partial Batch Handling.Prunes Ok Events On Partial Retry6522ms
Partial Batch Handling.Prunes Dropped Events On Partial Retry6516ms
Partial Batch Handling.Retries Only Retry Events From Partial6523ms
Partial Batch Handling.Partial Retry Preserves Uuids6517ms
Partial Batch Handling.Partial Retry Attempt Header Increments6521ms
Partial Batch Handling.Partial Retry Request Id Preserved6521ms
Partial Batch Handling.Respects Retry After On Partial8522ms
Partial Batch Handling.Unknown Result Treated As Terminal3516ms
Partial Batch Handling.Mixed Ok Drop Limited No Retry3520ms
Compression.Sends Gzip Content Encoding511ms
Compression.No Content Encoding When Disabled510ms
Compression.Compressed Body Is Decompressible510ms
Error Handling.Does Not Retry On Unknown 4Xx2511ms
Event Options.Cookieless Mode Override511ms
Event Options.Disable Skew Correction Override510ms
Event Options.Process Person Profile Override510ms
Event Options.Product Tour Id Override510ms
Event Options.Unset Options Omitted509ms
Event Options.Options Override In Batch513ms
Geoip And Historical Migration.Geoip Disable Injected Into Properties510ms
Geoip And Historical Migration.Historical Migration Set In Body510ms
Geoip And Historical Migration.Historical Migration Absent By Default509ms

Feature_Flags Tests

17/17 tests passed

View Details
TestStatusDuration
Request Payload.Request With Person Properties Device Id11ms
Request Payload.Flags Request Uses V2 Query Param8ms
Request Payload.Flags Request Hits Flags Path Not Decide9ms
Request Payload.Flags Request Omits Authorization Header10ms
Request Payload.Token In Flags Body Matches Init8ms
Request Payload.Groups Round Trip9ms
Request Payload.Groups Default To Empty Object9ms
Request Payload.Disable Geoip False Propagates As Geoip Disable False9ms
Request Payload.Disable Geoip Omitted Defaults To False9ms
Request Payload.Flag Keys To Evaluate Contains Only Requested Key9ms
Request Lifecycle.No Flags Request On Init Alone4ms
Request Lifecycle.No Flags Request On Normal Capture508ms
Request Lifecycle.Two Flag Calls Produce Two Remote Requests14ms
Request Lifecycle.Mock Response Value Is Returned To Caller10ms
Retry Behavior.Retries Flags On 502312ms
Retry Behavior.Retries Flags On 504312ms
Side Effect Events.Get Feature Flag Captures Feature Flag Called Event511ms

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants