feat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transform - #2361

Merged
felixweinberger merged 1 commit into
v2-2026-07-28from
fweinberger/codemod-gaps
Jun 24, 2026
Merged

feat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transform#2361
felixweinberger merged 1 commit into
v2-2026-07-28from
fweinberger/codemod-gaps

Conversation

@felixweinberger

Copy link
Copy Markdown
Contributor

Close 4 mechanical gaps in the v1→v2 codemod and delete a dead transform.

Motivation and Context

The migration-doc audit (#2360) found the codemod handles inputSchema/argsSchema/uriSchemaz.object() wrap but not outputSchema; drops the schema arg from client.request()/callTool() but not ctx.mcpReq.send(); and importMap is missing sdk/server/express.js + client/auth-extensions.js. The expressMiddlewareTransformallowedHosts rewrite is dead (every released v1.x already had string[]).

How Has This Been Tested?

codemod suite 348/348 (+7 new fixtures, 3 negative tests correctly inverted), typecheck, lint, docs:check.

Breaking Changes

None — codemod only.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

Additional context

Transform count 10→9. docs/migration/upgrade-to-v2.md HANDLED/NOT-HANDLED lists updated to match.

@felixweinberger
felixweinberger requested a review from a team as a code ownerJune 24, 2026 15:51
@changeset-bot

changeset-botBot commented Jun 24, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 693d091

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@modelcontextprotocol/codemodPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Jun 24, 2026

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/client@2361

@modelcontextprotocol/codemod

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/codemod@2361

@modelcontextprotocol/server

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server@2361

@modelcontextprotocol/server-legacy

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server-legacy@2361

@modelcontextprotocol/express

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/express@2361

@modelcontextprotocol/fastify

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/fastify@2361

@modelcontextprotocol/hono

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/hono@2361

@modelcontextprotocol/node

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/node@2361

commit: 3c0d716

@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch 2 times, most recently from c46d707 to 7cfe90eCompareJune 24, 2026 16:02
Comment threadpackages/codemod/src/migrations/v1-to-v2/transforms/index.ts
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch from 7cfe90e to 0d9215fCompareJune 24, 2026 16:52
Comment threadpackages/codemod/src/migrations/v1-to-v2/transforms/schemaParamRemoval.ts Outdated
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch 2 times, most recently from 404e24c to 3c0d716CompareJune 24, 2026 22:17
…leware transform
- registerTool: also wrap raw outputSchema with z.object() (already did inputSchema/argsSchema/uriSchema)
- importMap: + sdk/server/express.js, + sdk/server/middleware/hostHeaderValidation.js, + sdk/client/auth-extensions.js
- delete expressMiddlewareTransform: it rewrote hostHeaderValidation({allowedHosts:[...]}) -> hostHeaderValidation([...]),
but hostHeaderValidation was (string[]) in every released v1.x. The allowedHosts *option* on createMcpExpressApp /
SSEServerTransport is unchanged v1->v2 (only the import path moved); the transform targeted the wrong API.
- docs/migration/upgrade-to-v2.md: HANDLED/NOT-HANDLED lists updated to match
@felixweinbergerfelixweinberger changed the title fix(codemod): wrap outputSchema; drop ctx.send schema arg; importMap express/auth-extensions; delete dead expressMiddlewareTransformfeat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transformJun 24, 2026
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch from 3c0d716 to 693d091CompareJune 24, 2026 22:55
@felixweinberger
felixweinberger merged commit 8fa82f3 into v2-2026-07-28Jun 24, 2026
15 checks passed
@felixweinberger
felixweinberger deleted the fweinberger/codemod-gaps branch June 24, 2026 22:55

@claudeclaudeBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — codemod-only mechanical gap-closing; prior review feedback (changeset, README coverage prose, extra importMap entries) is addressed in this revision and the docs now match the shipped transforms.

Extended reasoning...

Overview

This PR is confined to the @modelcontextprotocol/codemod package plus migration/README docs: it adds an outputSchema z.object() wrap to mcpServerApiTransform, adds importMap entries (client/auth-extensions.js, server/express.js, server/middleware/hostHeaderValidation.js, client/middleware.js, shared/auth-utils.js), deletes the dead expressMiddlewareTransform, updates the migration guide/README coverage lists, and adds a patch changeset. No SDK runtime code is touched.

Security risks

None — the change affects a developer-run codemod tool and prose documentation only; no auth, transport, or protocol code paths are modified.

Level of scrutiny

Moderate-low. The codemod is a userland migration aid published as alpha; the worst failure mode is an import left unrewritten (surfaced by the documented tsc --noEmit step), not a runtime defect for SDK consumers. I verified the riskier earlier finding is not present in this revision: schemaParamRemoval.ts is unchanged (TARGET_METHODS is still request/callTool), so the previously flagged custom-method schema-stripping regression does not exist; the new sendRequest test is a negative guard consistent with that. The expressMiddleware deletion is backed by the existing migration-guide statement (from #2360) that every released v1.x already used the string[] signature, and the integration tests were updated to assert the call is left untouched while the import is still rewritten.

Other factors

All prior review threads are addressed: the changeset (codemod-v1-to-v2-gaps.md) now exists, the README no longer lists outputSchema wrapping as manual while correctly keeping the ctx.mcpReq.send() schema-arg drop manual (matching the unchanged transform), and the suggested client/middleware.js / shared/auth-utils.js importMap entries were added. New behavior has direct vitest fixtures (outputSchema wrap, no double-wrap, new import-path rewrites), the doc cross-link anchors (#probe-policy, #per-era-wire-codecs) resolve in support-2026-07-28.md, and the bug-hunting system found no bugs in this revision.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@felixweinberger
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transform - #2361

Merged
felixweinberger merged 1 commit into
v2-2026-07-28from
fweinberger/codemod-gaps
Jun 24, 2026
Merged

feat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transform#2361
felixweinberger merged 1 commit into
v2-2026-07-28from
fweinberger/codemod-gaps

Conversation

@felixweinberger

Copy link
Copy Markdown
Contributor

Close 4 mechanical gaps in the v1→v2 codemod and delete a dead transform.

Motivation and Context

The migration-doc audit (#2360) found the codemod handles inputSchema/argsSchema/uriSchemaz.object() wrap but not outputSchema; drops the schema arg from client.request()/callTool() but not ctx.mcpReq.send(); and importMap is missing sdk/server/express.js + client/auth-extensions.js. The expressMiddlewareTransformallowedHosts rewrite is dead (every released v1.x already had string[]).

How Has This Been Tested?

codemod suite 348/348 (+7 new fixtures, 3 negative tests correctly inverted), typecheck, lint, docs:check.

Breaking Changes

None — codemod only.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

Additional context

Transform count 10→9. docs/migration/upgrade-to-v2.md HANDLED/NOT-HANDLED lists updated to match.

@felixweinberger
felixweinberger requested a review from a team as a code ownerJune 24, 2026 15:51
@changeset-bot

changeset-botBot commented Jun 24, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 693d091

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@modelcontextprotocol/codemodPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Jun 24, 2026

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/client@2361

@modelcontextprotocol/codemod

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/codemod@2361

@modelcontextprotocol/server

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server@2361

@modelcontextprotocol/server-legacy

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server-legacy@2361

@modelcontextprotocol/express

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/express@2361

@modelcontextprotocol/fastify

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/fastify@2361

@modelcontextprotocol/hono

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/hono@2361

@modelcontextprotocol/node

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/node@2361

commit: 3c0d716

@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch 2 times, most recently from c46d707 to 7cfe90eCompareJune 24, 2026 16:02
Comment threadpackages/codemod/src/migrations/v1-to-v2/transforms/index.ts
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch from 7cfe90e to 0d9215fCompareJune 24, 2026 16:52
Comment threadpackages/codemod/src/migrations/v1-to-v2/transforms/schemaParamRemoval.ts Outdated
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch 2 times, most recently from 404e24c to 3c0d716CompareJune 24, 2026 22:17
…leware transform
- registerTool: also wrap raw outputSchema with z.object() (already did inputSchema/argsSchema/uriSchema)
- importMap: + sdk/server/express.js, + sdk/server/middleware/hostHeaderValidation.js, + sdk/client/auth-extensions.js
- delete expressMiddlewareTransform: it rewrote hostHeaderValidation({allowedHosts:[...]}) -> hostHeaderValidation([...]),
but hostHeaderValidation was (string[]) in every released v1.x. The allowedHosts *option* on createMcpExpressApp /
SSEServerTransport is unchanged v1->v2 (only the import path moved); the transform targeted the wrong API.
- docs/migration/upgrade-to-v2.md: HANDLED/NOT-HANDLED lists updated to match
@felixweinbergerfelixweinberger changed the title fix(codemod): wrap outputSchema; drop ctx.send schema arg; importMap express/auth-extensions; delete dead expressMiddlewareTransformfeat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transformJun 24, 2026
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch from 3c0d716 to 693d091CompareJune 24, 2026 22:55
@felixweinberger
felixweinberger merged commit 8fa82f3 into v2-2026-07-28Jun 24, 2026
15 checks passed
@felixweinberger
felixweinberger deleted the fweinberger/codemod-gaps branch June 24, 2026 22:55

@claudeclaudeBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — codemod-only mechanical gap-closing; prior review feedback (changeset, README coverage prose, extra importMap entries) is addressed in this revision and the docs now match the shipped transforms.

Extended reasoning...

Overview

This PR is confined to the @modelcontextprotocol/codemod package plus migration/README docs: it adds an outputSchema z.object() wrap to mcpServerApiTransform, adds importMap entries (client/auth-extensions.js, server/express.js, server/middleware/hostHeaderValidation.js, client/middleware.js, shared/auth-utils.js), deletes the dead expressMiddlewareTransform, updates the migration guide/README coverage lists, and adds a patch changeset. No SDK runtime code is touched.

Security risks

None — the change affects a developer-run codemod tool and prose documentation only; no auth, transport, or protocol code paths are modified.

Level of scrutiny

Moderate-low. The codemod is a userland migration aid published as alpha; the worst failure mode is an import left unrewritten (surfaced by the documented tsc --noEmit step), not a runtime defect for SDK consumers. I verified the riskier earlier finding is not present in this revision: schemaParamRemoval.ts is unchanged (TARGET_METHODS is still request/callTool), so the previously flagged custom-method schema-stripping regression does not exist; the new sendRequest test is a negative guard consistent with that. The expressMiddleware deletion is backed by the existing migration-guide statement (from #2360) that every released v1.x already used the string[] signature, and the integration tests were updated to assert the call is left untouched while the import is still rewritten.

Other factors

All prior review threads are addressed: the changeset (codemod-v1-to-v2-gaps.md) now exists, the README no longer lists outputSchema wrapping as manual while correctly keeping the ctx.mcpReq.send() schema-arg drop manual (matching the unchanged transform), and the suggested client/middleware.js / shared/auth-utils.js importMap entries were added. New behavior has direct vitest fixtures (outputSchema wrap, no double-wrap, new import-path rewrites), the doc cross-link anchors (#probe-policy, #per-era-wire-codecs) resolve in support-2026-07-28.md, and the bug-hunting system found no bugs in this revision.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@felixweinberger
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transform - #2361

Merged
felixweinberger merged 1 commit into
v2-2026-07-28from
fweinberger/codemod-gaps
Jun 24, 2026
Merged

feat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transform#2361
felixweinberger merged 1 commit into
v2-2026-07-28from
fweinberger/codemod-gaps

Conversation

@felixweinberger

Copy link
Copy Markdown
Contributor

Close 4 mechanical gaps in the v1→v2 codemod and delete a dead transform.

Motivation and Context

The migration-doc audit (#2360) found the codemod handles inputSchema/argsSchema/uriSchemaz.object() wrap but not outputSchema; drops the schema arg from client.request()/callTool() but not ctx.mcpReq.send(); and importMap is missing sdk/server/express.js + client/auth-extensions.js. The expressMiddlewareTransformallowedHosts rewrite is dead (every released v1.x already had string[]).

How Has This Been Tested?

codemod suite 348/348 (+7 new fixtures, 3 negative tests correctly inverted), typecheck, lint, docs:check.

Breaking Changes

None — codemod only.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

Additional context

Transform count 10→9. docs/migration/upgrade-to-v2.md HANDLED/NOT-HANDLED lists updated to match.

@felixweinberger
felixweinberger requested a review from a team as a code ownerJune 24, 2026 15:51
@changeset-bot

changeset-botBot commented Jun 24, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 693d091

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@modelcontextprotocol/codemodPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Jun 24, 2026

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/client@2361

@modelcontextprotocol/codemod

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/codemod@2361

@modelcontextprotocol/server

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server@2361

@modelcontextprotocol/server-legacy

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server-legacy@2361

@modelcontextprotocol/express

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/express@2361

@modelcontextprotocol/fastify

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/fastify@2361

@modelcontextprotocol/hono

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/hono@2361

@modelcontextprotocol/node

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/node@2361

commit: 3c0d716

@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch 2 times, most recently from c46d707 to 7cfe90eCompareJune 24, 2026 16:02
Comment threadpackages/codemod/src/migrations/v1-to-v2/transforms/index.ts
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch from 7cfe90e to 0d9215fCompareJune 24, 2026 16:52
Comment threadpackages/codemod/src/migrations/v1-to-v2/transforms/schemaParamRemoval.ts Outdated
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch 2 times, most recently from 404e24c to 3c0d716CompareJune 24, 2026 22:17
…leware transform
- registerTool: also wrap raw outputSchema with z.object() (already did inputSchema/argsSchema/uriSchema)
- importMap: + sdk/server/express.js, + sdk/server/middleware/hostHeaderValidation.js, + sdk/client/auth-extensions.js
- delete expressMiddlewareTransform: it rewrote hostHeaderValidation({allowedHosts:[...]}) -> hostHeaderValidation([...]),
but hostHeaderValidation was (string[]) in every released v1.x. The allowedHosts *option* on createMcpExpressApp /
SSEServerTransport is unchanged v1->v2 (only the import path moved); the transform targeted the wrong API.
- docs/migration/upgrade-to-v2.md: HANDLED/NOT-HANDLED lists updated to match
@felixweinbergerfelixweinberger changed the title fix(codemod): wrap outputSchema; drop ctx.send schema arg; importMap express/auth-extensions; delete dead expressMiddlewareTransformfeat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transformJun 24, 2026
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch from 3c0d716 to 693d091CompareJune 24, 2026 22:55
@felixweinberger
felixweinberger merged commit 8fa82f3 into v2-2026-07-28Jun 24, 2026
15 checks passed
@felixweinberger
felixweinberger deleted the fweinberger/codemod-gaps branch June 24, 2026 22:55

@claudeclaudeBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — codemod-only mechanical gap-closing; prior review feedback (changeset, README coverage prose, extra importMap entries) is addressed in this revision and the docs now match the shipped transforms.

Extended reasoning...

Overview

This PR is confined to the @modelcontextprotocol/codemod package plus migration/README docs: it adds an outputSchema z.object() wrap to mcpServerApiTransform, adds importMap entries (client/auth-extensions.js, server/express.js, server/middleware/hostHeaderValidation.js, client/middleware.js, shared/auth-utils.js), deletes the dead expressMiddlewareTransform, updates the migration guide/README coverage lists, and adds a patch changeset. No SDK runtime code is touched.

Security risks

None — the change affects a developer-run codemod tool and prose documentation only; no auth, transport, or protocol code paths are modified.

Level of scrutiny

Moderate-low. The codemod is a userland migration aid published as alpha; the worst failure mode is an import left unrewritten (surfaced by the documented tsc --noEmit step), not a runtime defect for SDK consumers. I verified the riskier earlier finding is not present in this revision: schemaParamRemoval.ts is unchanged (TARGET_METHODS is still request/callTool), so the previously flagged custom-method schema-stripping regression does not exist; the new sendRequest test is a negative guard consistent with that. The expressMiddleware deletion is backed by the existing migration-guide statement (from #2360) that every released v1.x already used the string[] signature, and the integration tests were updated to assert the call is left untouched while the import is still rewritten.

Other factors

All prior review threads are addressed: the changeset (codemod-v1-to-v2-gaps.md) now exists, the README no longer lists outputSchema wrapping as manual while correctly keeping the ctx.mcpReq.send() schema-arg drop manual (matching the unchanged transform), and the suggested client/middleware.js / shared/auth-utils.js importMap entries were added. New behavior has direct vitest fixtures (outputSchema wrap, no double-wrap, new import-path rewrites), the doc cross-link anchors (#probe-policy, #per-era-wire-codecs) resolve in support-2026-07-28.md, and the bug-hunting system found no bugs in this revision.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@felixweinberger
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transform - #2361

Merged
felixweinberger merged 1 commit into
v2-2026-07-28from
fweinberger/codemod-gaps
Jun 24, 2026
Merged

feat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transform#2361
felixweinberger merged 1 commit into
v2-2026-07-28from
fweinberger/codemod-gaps

Conversation

@felixweinberger

Copy link
Copy Markdown
Contributor

Close 4 mechanical gaps in the v1→v2 codemod and delete a dead transform.

Motivation and Context

The migration-doc audit (#2360) found the codemod handles inputSchema/argsSchema/uriSchemaz.object() wrap but not outputSchema; drops the schema arg from client.request()/callTool() but not ctx.mcpReq.send(); and importMap is missing sdk/server/express.js + client/auth-extensions.js. The expressMiddlewareTransformallowedHosts rewrite is dead (every released v1.x already had string[]).

How Has This Been Tested?

codemod suite 348/348 (+7 new fixtures, 3 negative tests correctly inverted), typecheck, lint, docs:check.

Breaking Changes

None — codemod only.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

Additional context

Transform count 10→9. docs/migration/upgrade-to-v2.md HANDLED/NOT-HANDLED lists updated to match.

@felixweinberger
felixweinberger requested a review from a team as a code ownerJune 24, 2026 15:51
@changeset-bot

changeset-botBot commented Jun 24, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 693d091

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@modelcontextprotocol/codemodPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Jun 24, 2026

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/client@2361

@modelcontextprotocol/codemod

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/codemod@2361

@modelcontextprotocol/server

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server@2361

@modelcontextprotocol/server-legacy

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server-legacy@2361

@modelcontextprotocol/express

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/express@2361

@modelcontextprotocol/fastify

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/fastify@2361

@modelcontextprotocol/hono

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/hono@2361

@modelcontextprotocol/node

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/node@2361

commit: 3c0d716

@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch 2 times, most recently from c46d707 to 7cfe90eCompareJune 24, 2026 16:02
Comment threadpackages/codemod/src/migrations/v1-to-v2/transforms/index.ts
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch from 7cfe90e to 0d9215fCompareJune 24, 2026 16:52
Comment threadpackages/codemod/src/migrations/v1-to-v2/transforms/schemaParamRemoval.ts Outdated
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch 2 times, most recently from 404e24c to 3c0d716CompareJune 24, 2026 22:17
…leware transform
- registerTool: also wrap raw outputSchema with z.object() (already did inputSchema/argsSchema/uriSchema)
- importMap: + sdk/server/express.js, + sdk/server/middleware/hostHeaderValidation.js, + sdk/client/auth-extensions.js
- delete expressMiddlewareTransform: it rewrote hostHeaderValidation({allowedHosts:[...]}) -> hostHeaderValidation([...]),
but hostHeaderValidation was (string[]) in every released v1.x. The allowedHosts *option* on createMcpExpressApp /
SSEServerTransport is unchanged v1->v2 (only the import path moved); the transform targeted the wrong API.
- docs/migration/upgrade-to-v2.md: HANDLED/NOT-HANDLED lists updated to match
@felixweinbergerfelixweinberger changed the title fix(codemod): wrap outputSchema; drop ctx.send schema arg; importMap express/auth-extensions; delete dead expressMiddlewareTransformfeat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transformJun 24, 2026
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch from 3c0d716 to 693d091CompareJune 24, 2026 22:55
@felixweinberger
felixweinberger merged commit 8fa82f3 into v2-2026-07-28Jun 24, 2026
15 checks passed
@felixweinberger
felixweinberger deleted the fweinberger/codemod-gaps branch June 24, 2026 22:55

@claudeclaudeBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — codemod-only mechanical gap-closing; prior review feedback (changeset, README coverage prose, extra importMap entries) is addressed in this revision and the docs now match the shipped transforms.

Extended reasoning...

Overview

This PR is confined to the @modelcontextprotocol/codemod package plus migration/README docs: it adds an outputSchema z.object() wrap to mcpServerApiTransform, adds importMap entries (client/auth-extensions.js, server/express.js, server/middleware/hostHeaderValidation.js, client/middleware.js, shared/auth-utils.js), deletes the dead expressMiddlewareTransform, updates the migration guide/README coverage lists, and adds a patch changeset. No SDK runtime code is touched.

Security risks

None — the change affects a developer-run codemod tool and prose documentation only; no auth, transport, or protocol code paths are modified.

Level of scrutiny

Moderate-low. The codemod is a userland migration aid published as alpha; the worst failure mode is an import left unrewritten (surfaced by the documented tsc --noEmit step), not a runtime defect for SDK consumers. I verified the riskier earlier finding is not present in this revision: schemaParamRemoval.ts is unchanged (TARGET_METHODS is still request/callTool), so the previously flagged custom-method schema-stripping regression does not exist; the new sendRequest test is a negative guard consistent with that. The expressMiddleware deletion is backed by the existing migration-guide statement (from #2360) that every released v1.x already used the string[] signature, and the integration tests were updated to assert the call is left untouched while the import is still rewritten.

Other factors

All prior review threads are addressed: the changeset (codemod-v1-to-v2-gaps.md) now exists, the README no longer lists outputSchema wrapping as manual while correctly keeping the ctx.mcpReq.send() schema-arg drop manual (matching the unchanged transform), and the suggested client/middleware.js / shared/auth-utils.js importMap entries were added. New behavior has direct vitest fixtures (outputSchema wrap, no double-wrap, new import-path rewrites), the doc cross-link anchors (#probe-policy, #per-era-wire-codecs) resolve in support-2026-07-28.md, and the bug-hunting system found no bugs in this revision.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@felixweinberger
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transform - #2361

Merged
felixweinberger merged 1 commit into
v2-2026-07-28from
fweinberger/codemod-gaps
Jun 24, 2026
Merged

feat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transform#2361
felixweinberger merged 1 commit into
v2-2026-07-28from
fweinberger/codemod-gaps

Conversation

@felixweinberger

Copy link
Copy Markdown
Contributor

Close 4 mechanical gaps in the v1→v2 codemod and delete a dead transform.

Motivation and Context

The migration-doc audit (#2360) found the codemod handles inputSchema/argsSchema/uriSchemaz.object() wrap but not outputSchema; drops the schema arg from client.request()/callTool() but not ctx.mcpReq.send(); and importMap is missing sdk/server/express.js + client/auth-extensions.js. The expressMiddlewareTransformallowedHosts rewrite is dead (every released v1.x already had string[]).

How Has This Been Tested?

codemod suite 348/348 (+7 new fixtures, 3 negative tests correctly inverted), typecheck, lint, docs:check.

Breaking Changes

None — codemod only.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

Additional context

Transform count 10→9. docs/migration/upgrade-to-v2.md HANDLED/NOT-HANDLED lists updated to match.

@felixweinberger
felixweinberger requested a review from a team as a code ownerJune 24, 2026 15:51
@changeset-bot

changeset-botBot commented Jun 24, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 693d091

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@modelcontextprotocol/codemodPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Jun 24, 2026

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/client@2361

@modelcontextprotocol/codemod

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/codemod@2361

@modelcontextprotocol/server

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server@2361

@modelcontextprotocol/server-legacy

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server-legacy@2361

@modelcontextprotocol/express

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/express@2361

@modelcontextprotocol/fastify

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/fastify@2361

@modelcontextprotocol/hono

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/hono@2361

@modelcontextprotocol/node

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/node@2361

commit: 3c0d716

@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch 2 times, most recently from c46d707 to 7cfe90eCompareJune 24, 2026 16:02
Comment threadpackages/codemod/src/migrations/v1-to-v2/transforms/index.ts
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch from 7cfe90e to 0d9215fCompareJune 24, 2026 16:52
Comment threadpackages/codemod/src/migrations/v1-to-v2/transforms/schemaParamRemoval.ts Outdated
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch 2 times, most recently from 404e24c to 3c0d716CompareJune 24, 2026 22:17
…leware transform
- registerTool: also wrap raw outputSchema with z.object() (already did inputSchema/argsSchema/uriSchema)
- importMap: + sdk/server/express.js, + sdk/server/middleware/hostHeaderValidation.js, + sdk/client/auth-extensions.js
- delete expressMiddlewareTransform: it rewrote hostHeaderValidation({allowedHosts:[...]}) -> hostHeaderValidation([...]),
but hostHeaderValidation was (string[]) in every released v1.x. The allowedHosts *option* on createMcpExpressApp /
SSEServerTransport is unchanged v1->v2 (only the import path moved); the transform targeted the wrong API.
- docs/migration/upgrade-to-v2.md: HANDLED/NOT-HANDLED lists updated to match
@felixweinbergerfelixweinberger changed the title fix(codemod): wrap outputSchema; drop ctx.send schema arg; importMap express/auth-extensions; delete dead expressMiddlewareTransformfeat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transformJun 24, 2026
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch from 3c0d716 to 693d091CompareJune 24, 2026 22:55
@felixweinberger
felixweinberger merged commit 8fa82f3 into v2-2026-07-28Jun 24, 2026
15 checks passed
@felixweinberger
felixweinberger deleted the fweinberger/codemod-gaps branch June 24, 2026 22:55

@claudeclaudeBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — codemod-only mechanical gap-closing; prior review feedback (changeset, README coverage prose, extra importMap entries) is addressed in this revision and the docs now match the shipped transforms.

Extended reasoning...

Overview

This PR is confined to the @modelcontextprotocol/codemod package plus migration/README docs: it adds an outputSchema z.object() wrap to mcpServerApiTransform, adds importMap entries (client/auth-extensions.js, server/express.js, server/middleware/hostHeaderValidation.js, client/middleware.js, shared/auth-utils.js), deletes the dead expressMiddlewareTransform, updates the migration guide/README coverage lists, and adds a patch changeset. No SDK runtime code is touched.

Security risks

None — the change affects a developer-run codemod tool and prose documentation only; no auth, transport, or protocol code paths are modified.

Level of scrutiny

Moderate-low. The codemod is a userland migration aid published as alpha; the worst failure mode is an import left unrewritten (surfaced by the documented tsc --noEmit step), not a runtime defect for SDK consumers. I verified the riskier earlier finding is not present in this revision: schemaParamRemoval.ts is unchanged (TARGET_METHODS is still request/callTool), so the previously flagged custom-method schema-stripping regression does not exist; the new sendRequest test is a negative guard consistent with that. The expressMiddleware deletion is backed by the existing migration-guide statement (from #2360) that every released v1.x already used the string[] signature, and the integration tests were updated to assert the call is left untouched while the import is still rewritten.

Other factors

All prior review threads are addressed: the changeset (codemod-v1-to-v2-gaps.md) now exists, the README no longer lists outputSchema wrapping as manual while correctly keeping the ctx.mcpReq.send() schema-arg drop manual (matching the unchanged transform), and the suggested client/middleware.js / shared/auth-utils.js importMap entries were added. New behavior has direct vitest fixtures (outputSchema wrap, no double-wrap, new import-path rewrites), the doc cross-link anchors (#probe-policy, #per-era-wire-codecs) resolve in support-2026-07-28.md, and the bug-hunting system found no bugs in this revision.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@felixweinberger
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transform - #2361

Merged
felixweinberger merged 1 commit into
v2-2026-07-28from
fweinberger/codemod-gaps
Jun 24, 2026
Merged

feat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transform#2361
felixweinberger merged 1 commit into
v2-2026-07-28from
fweinberger/codemod-gaps

Conversation

@felixweinberger

Copy link
Copy Markdown
Contributor

Close 4 mechanical gaps in the v1→v2 codemod and delete a dead transform.

Motivation and Context

The migration-doc audit (#2360) found the codemod handles inputSchema/argsSchema/uriSchemaz.object() wrap but not outputSchema; drops the schema arg from client.request()/callTool() but not ctx.mcpReq.send(); and importMap is missing sdk/server/express.js + client/auth-extensions.js. The expressMiddlewareTransformallowedHosts rewrite is dead (every released v1.x already had string[]).

How Has This Been Tested?

codemod suite 348/348 (+7 new fixtures, 3 negative tests correctly inverted), typecheck, lint, docs:check.

Breaking Changes

None — codemod only.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

Additional context

Transform count 10→9. docs/migration/upgrade-to-v2.md HANDLED/NOT-HANDLED lists updated to match.

@felixweinberger
felixweinberger requested a review from a team as a code ownerJune 24, 2026 15:51
@changeset-bot

changeset-botBot commented Jun 24, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 693d091

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@modelcontextprotocol/codemodPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Jun 24, 2026

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/client@2361

@modelcontextprotocol/codemod

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/codemod@2361

@modelcontextprotocol/server

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server@2361

@modelcontextprotocol/server-legacy

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server-legacy@2361

@modelcontextprotocol/express

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/express@2361

@modelcontextprotocol/fastify

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/fastify@2361

@modelcontextprotocol/hono

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/hono@2361

@modelcontextprotocol/node

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/node@2361

commit: 3c0d716

@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch 2 times, most recently from c46d707 to 7cfe90eCompareJune 24, 2026 16:02
Comment threadpackages/codemod/src/migrations/v1-to-v2/transforms/index.ts
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch from 7cfe90e to 0d9215fCompareJune 24, 2026 16:52
Comment threadpackages/codemod/src/migrations/v1-to-v2/transforms/schemaParamRemoval.ts Outdated
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch 2 times, most recently from 404e24c to 3c0d716CompareJune 24, 2026 22:17
…leware transform
- registerTool: also wrap raw outputSchema with z.object() (already did inputSchema/argsSchema/uriSchema)
- importMap: + sdk/server/express.js, + sdk/server/middleware/hostHeaderValidation.js, + sdk/client/auth-extensions.js
- delete expressMiddlewareTransform: it rewrote hostHeaderValidation({allowedHosts:[...]}) -> hostHeaderValidation([...]),
but hostHeaderValidation was (string[]) in every released v1.x. The allowedHosts *option* on createMcpExpressApp /
SSEServerTransport is unchanged v1->v2 (only the import path moved); the transform targeted the wrong API.
- docs/migration/upgrade-to-v2.md: HANDLED/NOT-HANDLED lists updated to match
@felixweinbergerfelixweinberger changed the title fix(codemod): wrap outputSchema; drop ctx.send schema arg; importMap express/auth-extensions; delete dead expressMiddlewareTransformfeat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transformJun 24, 2026
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch from 3c0d716 to 693d091CompareJune 24, 2026 22:55
@felixweinberger
felixweinberger merged commit 8fa82f3 into v2-2026-07-28Jun 24, 2026
15 checks passed
@felixweinberger
felixweinberger deleted the fweinberger/codemod-gaps branch June 24, 2026 22:55

@claudeclaudeBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — codemod-only mechanical gap-closing; prior review feedback (changeset, README coverage prose, extra importMap entries) is addressed in this revision and the docs now match the shipped transforms.

Extended reasoning...

Overview

This PR is confined to the @modelcontextprotocol/codemod package plus migration/README docs: it adds an outputSchema z.object() wrap to mcpServerApiTransform, adds importMap entries (client/auth-extensions.js, server/express.js, server/middleware/hostHeaderValidation.js, client/middleware.js, shared/auth-utils.js), deletes the dead expressMiddlewareTransform, updates the migration guide/README coverage lists, and adds a patch changeset. No SDK runtime code is touched.

Security risks

None — the change affects a developer-run codemod tool and prose documentation only; no auth, transport, or protocol code paths are modified.

Level of scrutiny

Moderate-low. The codemod is a userland migration aid published as alpha; the worst failure mode is an import left unrewritten (surfaced by the documented tsc --noEmit step), not a runtime defect for SDK consumers. I verified the riskier earlier finding is not present in this revision: schemaParamRemoval.ts is unchanged (TARGET_METHODS is still request/callTool), so the previously flagged custom-method schema-stripping regression does not exist; the new sendRequest test is a negative guard consistent with that. The expressMiddleware deletion is backed by the existing migration-guide statement (from #2360) that every released v1.x already used the string[] signature, and the integration tests were updated to assert the call is left untouched while the import is still rewritten.

Other factors

All prior review threads are addressed: the changeset (codemod-v1-to-v2-gaps.md) now exists, the README no longer lists outputSchema wrapping as manual while correctly keeping the ctx.mcpReq.send() schema-arg drop manual (matching the unchanged transform), and the suggested client/middleware.js / shared/auth-utils.js importMap entries were added. New behavior has direct vitest fixtures (outputSchema wrap, no double-wrap, new import-path rewrites), the doc cross-link anchors (#probe-policy, #per-era-wire-codecs) resolve in support-2026-07-28.md, and the bug-hunting system found no bugs in this revision.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@felixweinberger
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transform - #2361

Merged
felixweinberger merged 1 commit into
v2-2026-07-28from
fweinberger/codemod-gaps
Jun 24, 2026
Merged

feat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transform#2361
felixweinberger merged 1 commit into
v2-2026-07-28from
fweinberger/codemod-gaps

Conversation

@felixweinberger

Copy link
Copy Markdown
Contributor

Close 4 mechanical gaps in the v1→v2 codemod and delete a dead transform.

Motivation and Context

The migration-doc audit (#2360) found the codemod handles inputSchema/argsSchema/uriSchemaz.object() wrap but not outputSchema; drops the schema arg from client.request()/callTool() but not ctx.mcpReq.send(); and importMap is missing sdk/server/express.js + client/auth-extensions.js. The expressMiddlewareTransformallowedHosts rewrite is dead (every released v1.x already had string[]).

How Has This Been Tested?

codemod suite 348/348 (+7 new fixtures, 3 negative tests correctly inverted), typecheck, lint, docs:check.

Breaking Changes

None — codemod only.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

Additional context

Transform count 10→9. docs/migration/upgrade-to-v2.md HANDLED/NOT-HANDLED lists updated to match.

@felixweinberger
felixweinberger requested a review from a team as a code ownerJune 24, 2026 15:51
@changeset-bot

changeset-botBot commented Jun 24, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 693d091

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@modelcontextprotocol/codemodPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Jun 24, 2026

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/client@2361

@modelcontextprotocol/codemod

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/codemod@2361

@modelcontextprotocol/server

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server@2361

@modelcontextprotocol/server-legacy

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server-legacy@2361

@modelcontextprotocol/express

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/express@2361

@modelcontextprotocol/fastify

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/fastify@2361

@modelcontextprotocol/hono

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/hono@2361

@modelcontextprotocol/node

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/node@2361

commit: 3c0d716

@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch 2 times, most recently from c46d707 to 7cfe90eCompareJune 24, 2026 16:02
Comment threadpackages/codemod/src/migrations/v1-to-v2/transforms/index.ts
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch from 7cfe90e to 0d9215fCompareJune 24, 2026 16:52
Comment threadpackages/codemod/src/migrations/v1-to-v2/transforms/schemaParamRemoval.ts Outdated
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch 2 times, most recently from 404e24c to 3c0d716CompareJune 24, 2026 22:17
…leware transform
- registerTool: also wrap raw outputSchema with z.object() (already did inputSchema/argsSchema/uriSchema)
- importMap: + sdk/server/express.js, + sdk/server/middleware/hostHeaderValidation.js, + sdk/client/auth-extensions.js
- delete expressMiddlewareTransform: it rewrote hostHeaderValidation({allowedHosts:[...]}) -> hostHeaderValidation([...]),
but hostHeaderValidation was (string[]) in every released v1.x. The allowedHosts *option* on createMcpExpressApp /
SSEServerTransport is unchanged v1->v2 (only the import path moved); the transform targeted the wrong API.
- docs/migration/upgrade-to-v2.md: HANDLED/NOT-HANDLED lists updated to match
@felixweinbergerfelixweinberger changed the title fix(codemod): wrap outputSchema; drop ctx.send schema arg; importMap express/auth-extensions; delete dead expressMiddlewareTransformfeat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transformJun 24, 2026
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch from 3c0d716 to 693d091CompareJune 24, 2026 22:55
@felixweinberger
felixweinberger merged commit 8fa82f3 into v2-2026-07-28Jun 24, 2026
15 checks passed
@felixweinberger
felixweinberger deleted the fweinberger/codemod-gaps branch June 24, 2026 22:55

@claudeclaudeBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — codemod-only mechanical gap-closing; prior review feedback (changeset, README coverage prose, extra importMap entries) is addressed in this revision and the docs now match the shipped transforms.

Extended reasoning...

Overview

This PR is confined to the @modelcontextprotocol/codemod package plus migration/README docs: it adds an outputSchema z.object() wrap to mcpServerApiTransform, adds importMap entries (client/auth-extensions.js, server/express.js, server/middleware/hostHeaderValidation.js, client/middleware.js, shared/auth-utils.js), deletes the dead expressMiddlewareTransform, updates the migration guide/README coverage lists, and adds a patch changeset. No SDK runtime code is touched.

Security risks

None — the change affects a developer-run codemod tool and prose documentation only; no auth, transport, or protocol code paths are modified.

Level of scrutiny

Moderate-low. The codemod is a userland migration aid published as alpha; the worst failure mode is an import left unrewritten (surfaced by the documented tsc --noEmit step), not a runtime defect for SDK consumers. I verified the riskier earlier finding is not present in this revision: schemaParamRemoval.ts is unchanged (TARGET_METHODS is still request/callTool), so the previously flagged custom-method schema-stripping regression does not exist; the new sendRequest test is a negative guard consistent with that. The expressMiddleware deletion is backed by the existing migration-guide statement (from #2360) that every released v1.x already used the string[] signature, and the integration tests were updated to assert the call is left untouched while the import is still rewritten.

Other factors

All prior review threads are addressed: the changeset (codemod-v1-to-v2-gaps.md) now exists, the README no longer lists outputSchema wrapping as manual while correctly keeping the ctx.mcpReq.send() schema-arg drop manual (matching the unchanged transform), and the suggested client/middleware.js / shared/auth-utils.js importMap entries were added. New behavior has direct vitest fixtures (outputSchema wrap, no double-wrap, new import-path rewrites), the doc cross-link anchors (#probe-policy, #per-era-wire-codecs) resolve in support-2026-07-28.md, and the bug-hunting system found no bugs in this revision.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@felixweinberger
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transform - #2361

Merged
felixweinberger merged 1 commit into
v2-2026-07-28from
fweinberger/codemod-gaps
Jun 24, 2026
Merged

feat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transform#2361
felixweinberger merged 1 commit into
v2-2026-07-28from
fweinberger/codemod-gaps

Conversation

@felixweinberger

Copy link
Copy Markdown
Contributor

Close 4 mechanical gaps in the v1→v2 codemod and delete a dead transform.

Motivation and Context

The migration-doc audit (#2360) found the codemod handles inputSchema/argsSchema/uriSchemaz.object() wrap but not outputSchema; drops the schema arg from client.request()/callTool() but not ctx.mcpReq.send(); and importMap is missing sdk/server/express.js + client/auth-extensions.js. The expressMiddlewareTransformallowedHosts rewrite is dead (every released v1.x already had string[]).

How Has This Been Tested?

codemod suite 348/348 (+7 new fixtures, 3 negative tests correctly inverted), typecheck, lint, docs:check.

Breaking Changes

None — codemod only.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

Additional context

Transform count 10→9. docs/migration/upgrade-to-v2.md HANDLED/NOT-HANDLED lists updated to match.

@felixweinberger
felixweinberger requested a review from a team as a code ownerJune 24, 2026 15:51
@changeset-bot

changeset-botBot commented Jun 24, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 693d091

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@modelcontextprotocol/codemodPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Jun 24, 2026

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/client@2361

@modelcontextprotocol/codemod

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/codemod@2361

@modelcontextprotocol/server

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server@2361

@modelcontextprotocol/server-legacy

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/server-legacy@2361

@modelcontextprotocol/express

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/express@2361

@modelcontextprotocol/fastify

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/fastify@2361

@modelcontextprotocol/hono

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/hono@2361

@modelcontextprotocol/node

npm i https://pkg.pr.new/modelcontextprotocol/typescript-sdk/@modelcontextprotocol/node@2361

commit: 3c0d716

@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch 2 times, most recently from c46d707 to 7cfe90eCompareJune 24, 2026 16:02
Comment threadpackages/codemod/src/migrations/v1-to-v2/transforms/index.ts
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch from 7cfe90e to 0d9215fCompareJune 24, 2026 16:52
Comment threadpackages/codemod/src/migrations/v1-to-v2/transforms/schemaParamRemoval.ts Outdated
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch 2 times, most recently from 404e24c to 3c0d716CompareJune 24, 2026 22:17
…leware transform
- registerTool: also wrap raw outputSchema with z.object() (already did inputSchema/argsSchema/uriSchema)
- importMap: + sdk/server/express.js, + sdk/server/middleware/hostHeaderValidation.js, + sdk/client/auth-extensions.js
- delete expressMiddlewareTransform: it rewrote hostHeaderValidation({allowedHosts:[...]}) -> hostHeaderValidation([...]),
but hostHeaderValidation was (string[]) in every released v1.x. The allowedHosts *option* on createMcpExpressApp /
SSEServerTransport is unchanged v1->v2 (only the import path moved); the transform targeted the wrong API.
- docs/migration/upgrade-to-v2.md: HANDLED/NOT-HANDLED lists updated to match
@felixweinbergerfelixweinberger changed the title fix(codemod): wrap outputSchema; drop ctx.send schema arg; importMap express/auth-extensions; delete dead expressMiddlewareTransformfeat(codemod): close v1-to-v2 mechanical gaps — outputSchema wrap, importMap entries; drop dead expressMiddleware transformJun 24, 2026
@felixweinberger
felixweinbergerforce-pushed the fweinberger/codemod-gaps branch from 3c0d716 to 693d091CompareJune 24, 2026 22:55
@felixweinberger
felixweinberger merged commit 8fa82f3 into v2-2026-07-28Jun 24, 2026
15 checks passed
@felixweinberger
felixweinberger deleted the fweinberger/codemod-gaps branch June 24, 2026 22:55

@claudeclaudeBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — codemod-only mechanical gap-closing; prior review feedback (changeset, README coverage prose, extra importMap entries) is addressed in this revision and the docs now match the shipped transforms.

Extended reasoning...

Overview

This PR is confined to the @modelcontextprotocol/codemod package plus migration/README docs: it adds an outputSchema z.object() wrap to mcpServerApiTransform, adds importMap entries (client/auth-extensions.js, server/express.js, server/middleware/hostHeaderValidation.js, client/middleware.js, shared/auth-utils.js), deletes the dead expressMiddlewareTransform, updates the migration guide/README coverage lists, and adds a patch changeset. No SDK runtime code is touched.

Security risks

None — the change affects a developer-run codemod tool and prose documentation only; no auth, transport, or protocol code paths are modified.

Level of scrutiny

Moderate-low. The codemod is a userland migration aid published as alpha; the worst failure mode is an import left unrewritten (surfaced by the documented tsc --noEmit step), not a runtime defect for SDK consumers. I verified the riskier earlier finding is not present in this revision: schemaParamRemoval.ts is unchanged (TARGET_METHODS is still request/callTool), so the previously flagged custom-method schema-stripping regression does not exist; the new sendRequest test is a negative guard consistent with that. The expressMiddleware deletion is backed by the existing migration-guide statement (from #2360) that every released v1.x already used the string[] signature, and the integration tests were updated to assert the call is left untouched while the import is still rewritten.

Other factors

All prior review threads are addressed: the changeset (codemod-v1-to-v2-gaps.md) now exists, the README no longer lists outputSchema wrapping as manual while correctly keeping the ctx.mcpReq.send() schema-arg drop manual (matching the unchanged transform), and the suggested client/middleware.js / shared/auth-utils.js importMap entries were added. New behavior has direct vitest fixtures (outputSchema wrap, no double-wrap, new import-path rewrites), the doc cross-link anchors (#probe-policy, #per-era-wire-codecs) resolve in support-2026-07-28.md, and the bug-hunting system found no bugs in this revision.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@felixweinberger