fix(web): return 405 for GET /api/mcp instead of hanging connection - #1064

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan-kellam/fix-SOU-827
Mar 31, 2026
Merged

fix(web): return 405 for GET /api/mcp instead of hanging connection#1064
brendan-kellam merged 2 commits into
mainfrom
brendan-kellam/fix-SOU-827

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Mar 31, 2026

Copy link
Copy Markdown
Contributor

Summary

  • The GET /api/mcp handler opened an SSE stream that never flushed its HTTP response headers, causing clients to hang until timeout (0 bytes received)
  • Sourcebot does not send server-initiated messages, so the GET SSE stream serves no purpose
  • Per the MCP Streamable HTTP spec, servers that do not offer a GET SSE stream MUST return 405 Method Not Allowed

Fixes#1061

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes
    • Fixed an issue where the MCP API endpoint would hang when processing certain requests; it now properly returns a 405 Method Not Allowed response per the MCP Streamable HTTP specification.

The GET SSE stream is only used for server-initiated messages, which
Sourcebot does not send. Per the MCP Streamable HTTP spec, servers that
do not offer a GET SSE stream MUST return 405 Method Not Allowed.
Previously the handler opened an SSE stream that never flushed its HTTP
headers, causing clients to hang until timeout.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Mar 31, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 5a899a03-a11f-460e-9298-64f61b3dca1e

📥 Commits

Reviewing files that changed from the base of the PR and between f8e21d6 and 4920101.

📒 Files selected for processing (2)
  • CHANGELOG.md
  • packages/web/src/app/api/(server)/mcp/route.ts

Walkthrough

The changes fix a bug where GET requests to /api/mcp were hanging indefinitely without sending an HTTP response. The GET handler has been replaced to return a 405 Method Not Allowed status with proper HTTP headers, conforming to the MCP Streamable HTTP transport specification.

Changes

Cohort / File(s)Summary
Changelog Documentation
CHANGELOG.md
Added entry in Unreleased section documenting the fix: GET requests to /api/mcp now return HTTP 405 Method Not Allowed instead of hanging.
Route Handler
packages/web/src/app/api/(server)/mcp/route.ts
Replaced GET handler implementation that was causing hangs. Old handler performed session validation and auth checks; new handler returns fixed 405 response with Allow: POST, DELETE header, removing all session lookup and authorization logic.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan-kellam/fix-SOU-827

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 470360d into mainMar 31, 2026
7 checks passed
@brendan-kellam
brendan-kellam deleted the brendan-kellam/fix-SOU-827 branch March 31, 2026 22:44
@github-actionsgithub-actionsBot mentioned this pull request Mar 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[bug] GET /api/mcp does not return HTTP response when valid session ID is provided (Streamable HTTP transport violation)

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(web): return 405 for GET /api/mcp instead of hanging connection - #1064

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan-kellam/fix-SOU-827
Mar 31, 2026
Merged

fix(web): return 405 for GET /api/mcp instead of hanging connection#1064
brendan-kellam merged 2 commits into
mainfrom
brendan-kellam/fix-SOU-827

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Mar 31, 2026

Copy link
Copy Markdown
Contributor

Summary

  • The GET /api/mcp handler opened an SSE stream that never flushed its HTTP response headers, causing clients to hang until timeout (0 bytes received)
  • Sourcebot does not send server-initiated messages, so the GET SSE stream serves no purpose
  • Per the MCP Streamable HTTP spec, servers that do not offer a GET SSE stream MUST return 405 Method Not Allowed

Fixes#1061

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes
    • Fixed an issue where the MCP API endpoint would hang when processing certain requests; it now properly returns a 405 Method Not Allowed response per the MCP Streamable HTTP specification.

The GET SSE stream is only used for server-initiated messages, which
Sourcebot does not send. Per the MCP Streamable HTTP spec, servers that
do not offer a GET SSE stream MUST return 405 Method Not Allowed.
Previously the handler opened an SSE stream that never flushed its HTTP
headers, causing clients to hang until timeout.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Mar 31, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 5a899a03-a11f-460e-9298-64f61b3dca1e

📥 Commits

Reviewing files that changed from the base of the PR and between f8e21d6 and 4920101.

📒 Files selected for processing (2)
  • CHANGELOG.md
  • packages/web/src/app/api/(server)/mcp/route.ts

Walkthrough

The changes fix a bug where GET requests to /api/mcp were hanging indefinitely without sending an HTTP response. The GET handler has been replaced to return a 405 Method Not Allowed status with proper HTTP headers, conforming to the MCP Streamable HTTP transport specification.

Changes

Cohort / File(s)Summary
Changelog Documentation
CHANGELOG.md
Added entry in Unreleased section documenting the fix: GET requests to /api/mcp now return HTTP 405 Method Not Allowed instead of hanging.
Route Handler
packages/web/src/app/api/(server)/mcp/route.ts
Replaced GET handler implementation that was causing hangs. Old handler performed session validation and auth checks; new handler returns fixed 405 response with Allow: POST, DELETE header, removing all session lookup and authorization logic.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan-kellam/fix-SOU-827

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 470360d into mainMar 31, 2026
7 checks passed
@brendan-kellam
brendan-kellam deleted the brendan-kellam/fix-SOU-827 branch March 31, 2026 22:44
@github-actionsgithub-actionsBot mentioned this pull request Mar 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[bug] GET /api/mcp does not return HTTP response when valid session ID is provided (Streamable HTTP transport violation)

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(web): return 405 for GET /api/mcp instead of hanging connection - #1064

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan-kellam/fix-SOU-827
Mar 31, 2026
Merged

fix(web): return 405 for GET /api/mcp instead of hanging connection#1064
brendan-kellam merged 2 commits into
mainfrom
brendan-kellam/fix-SOU-827

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Mar 31, 2026

Copy link
Copy Markdown
Contributor

Summary

  • The GET /api/mcp handler opened an SSE stream that never flushed its HTTP response headers, causing clients to hang until timeout (0 bytes received)
  • Sourcebot does not send server-initiated messages, so the GET SSE stream serves no purpose
  • Per the MCP Streamable HTTP spec, servers that do not offer a GET SSE stream MUST return 405 Method Not Allowed

Fixes#1061

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes
    • Fixed an issue where the MCP API endpoint would hang when processing certain requests; it now properly returns a 405 Method Not Allowed response per the MCP Streamable HTTP specification.

The GET SSE stream is only used for server-initiated messages, which
Sourcebot does not send. Per the MCP Streamable HTTP spec, servers that
do not offer a GET SSE stream MUST return 405 Method Not Allowed.
Previously the handler opened an SSE stream that never flushed its HTTP
headers, causing clients to hang until timeout.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Mar 31, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 5a899a03-a11f-460e-9298-64f61b3dca1e

📥 Commits

Reviewing files that changed from the base of the PR and between f8e21d6 and 4920101.

📒 Files selected for processing (2)
  • CHANGELOG.md
  • packages/web/src/app/api/(server)/mcp/route.ts

Walkthrough

The changes fix a bug where GET requests to /api/mcp were hanging indefinitely without sending an HTTP response. The GET handler has been replaced to return a 405 Method Not Allowed status with proper HTTP headers, conforming to the MCP Streamable HTTP transport specification.

Changes

Cohort / File(s)Summary
Changelog Documentation
CHANGELOG.md
Added entry in Unreleased section documenting the fix: GET requests to /api/mcp now return HTTP 405 Method Not Allowed instead of hanging.
Route Handler
packages/web/src/app/api/(server)/mcp/route.ts
Replaced GET handler implementation that was causing hangs. Old handler performed session validation and auth checks; new handler returns fixed 405 response with Allow: POST, DELETE header, removing all session lookup and authorization logic.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan-kellam/fix-SOU-827

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 470360d into mainMar 31, 2026
7 checks passed
@brendan-kellam
brendan-kellam deleted the brendan-kellam/fix-SOU-827 branch March 31, 2026 22:44
@github-actionsgithub-actionsBot mentioned this pull request Mar 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[bug] GET /api/mcp does not return HTTP response when valid session ID is provided (Streamable HTTP transport violation)

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(web): return 405 for GET /api/mcp instead of hanging connection - #1064

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan-kellam/fix-SOU-827
Mar 31, 2026
Merged

fix(web): return 405 for GET /api/mcp instead of hanging connection#1064
brendan-kellam merged 2 commits into
mainfrom
brendan-kellam/fix-SOU-827

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Mar 31, 2026

Copy link
Copy Markdown
Contributor

Summary

  • The GET /api/mcp handler opened an SSE stream that never flushed its HTTP response headers, causing clients to hang until timeout (0 bytes received)
  • Sourcebot does not send server-initiated messages, so the GET SSE stream serves no purpose
  • Per the MCP Streamable HTTP spec, servers that do not offer a GET SSE stream MUST return 405 Method Not Allowed

Fixes#1061

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes
    • Fixed an issue where the MCP API endpoint would hang when processing certain requests; it now properly returns a 405 Method Not Allowed response per the MCP Streamable HTTP specification.

The GET SSE stream is only used for server-initiated messages, which
Sourcebot does not send. Per the MCP Streamable HTTP spec, servers that
do not offer a GET SSE stream MUST return 405 Method Not Allowed.
Previously the handler opened an SSE stream that never flushed its HTTP
headers, causing clients to hang until timeout.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Mar 31, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 5a899a03-a11f-460e-9298-64f61b3dca1e

📥 Commits

Reviewing files that changed from the base of the PR and between f8e21d6 and 4920101.

📒 Files selected for processing (2)
  • CHANGELOG.md
  • packages/web/src/app/api/(server)/mcp/route.ts

Walkthrough

The changes fix a bug where GET requests to /api/mcp were hanging indefinitely without sending an HTTP response. The GET handler has been replaced to return a 405 Method Not Allowed status with proper HTTP headers, conforming to the MCP Streamable HTTP transport specification.

Changes

Cohort / File(s)Summary
Changelog Documentation
CHANGELOG.md
Added entry in Unreleased section documenting the fix: GET requests to /api/mcp now return HTTP 405 Method Not Allowed instead of hanging.
Route Handler
packages/web/src/app/api/(server)/mcp/route.ts
Replaced GET handler implementation that was causing hangs. Old handler performed session validation and auth checks; new handler returns fixed 405 response with Allow: POST, DELETE header, removing all session lookup and authorization logic.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan-kellam/fix-SOU-827

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 470360d into mainMar 31, 2026
7 checks passed
@brendan-kellam
brendan-kellam deleted the brendan-kellam/fix-SOU-827 branch March 31, 2026 22:44
@github-actionsgithub-actionsBot mentioned this pull request Mar 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[bug] GET /api/mcp does not return HTTP response when valid session ID is provided (Streamable HTTP transport violation)

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(web): return 405 for GET /api/mcp instead of hanging connection - #1064

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan-kellam/fix-SOU-827
Mar 31, 2026
Merged

fix(web): return 405 for GET /api/mcp instead of hanging connection#1064
brendan-kellam merged 2 commits into
mainfrom
brendan-kellam/fix-SOU-827

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Mar 31, 2026

Copy link
Copy Markdown
Contributor

Summary

  • The GET /api/mcp handler opened an SSE stream that never flushed its HTTP response headers, causing clients to hang until timeout (0 bytes received)
  • Sourcebot does not send server-initiated messages, so the GET SSE stream serves no purpose
  • Per the MCP Streamable HTTP spec, servers that do not offer a GET SSE stream MUST return 405 Method Not Allowed

Fixes#1061

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes
    • Fixed an issue where the MCP API endpoint would hang when processing certain requests; it now properly returns a 405 Method Not Allowed response per the MCP Streamable HTTP specification.

The GET SSE stream is only used for server-initiated messages, which
Sourcebot does not send. Per the MCP Streamable HTTP spec, servers that
do not offer a GET SSE stream MUST return 405 Method Not Allowed.
Previously the handler opened an SSE stream that never flushed its HTTP
headers, causing clients to hang until timeout.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Mar 31, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 5a899a03-a11f-460e-9298-64f61b3dca1e

📥 Commits

Reviewing files that changed from the base of the PR and between f8e21d6 and 4920101.

📒 Files selected for processing (2)
  • CHANGELOG.md
  • packages/web/src/app/api/(server)/mcp/route.ts

Walkthrough

The changes fix a bug where GET requests to /api/mcp were hanging indefinitely without sending an HTTP response. The GET handler has been replaced to return a 405 Method Not Allowed status with proper HTTP headers, conforming to the MCP Streamable HTTP transport specification.

Changes

Cohort / File(s)Summary
Changelog Documentation
CHANGELOG.md
Added entry in Unreleased section documenting the fix: GET requests to /api/mcp now return HTTP 405 Method Not Allowed instead of hanging.
Route Handler
packages/web/src/app/api/(server)/mcp/route.ts
Replaced GET handler implementation that was causing hangs. Old handler performed session validation and auth checks; new handler returns fixed 405 response with Allow: POST, DELETE header, removing all session lookup and authorization logic.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan-kellam/fix-SOU-827

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 470360d into mainMar 31, 2026
7 checks passed
@brendan-kellam
brendan-kellam deleted the brendan-kellam/fix-SOU-827 branch March 31, 2026 22:44
@github-actionsgithub-actionsBot mentioned this pull request Mar 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[bug] GET /api/mcp does not return HTTP response when valid session ID is provided (Streamable HTTP transport violation)

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(web): return 405 for GET /api/mcp instead of hanging connection - #1064

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan-kellam/fix-SOU-827
Mar 31, 2026
Merged

fix(web): return 405 for GET /api/mcp instead of hanging connection#1064
brendan-kellam merged 2 commits into
mainfrom
brendan-kellam/fix-SOU-827

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Mar 31, 2026

Copy link
Copy Markdown
Contributor

Summary

  • The GET /api/mcp handler opened an SSE stream that never flushed its HTTP response headers, causing clients to hang until timeout (0 bytes received)
  • Sourcebot does not send server-initiated messages, so the GET SSE stream serves no purpose
  • Per the MCP Streamable HTTP spec, servers that do not offer a GET SSE stream MUST return 405 Method Not Allowed

Fixes#1061

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes
    • Fixed an issue where the MCP API endpoint would hang when processing certain requests; it now properly returns a 405 Method Not Allowed response per the MCP Streamable HTTP specification.

The GET SSE stream is only used for server-initiated messages, which
Sourcebot does not send. Per the MCP Streamable HTTP spec, servers that
do not offer a GET SSE stream MUST return 405 Method Not Allowed.
Previously the handler opened an SSE stream that never flushed its HTTP
headers, causing clients to hang until timeout.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Mar 31, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 5a899a03-a11f-460e-9298-64f61b3dca1e

📥 Commits

Reviewing files that changed from the base of the PR and between f8e21d6 and 4920101.

📒 Files selected for processing (2)
  • CHANGELOG.md
  • packages/web/src/app/api/(server)/mcp/route.ts

Walkthrough

The changes fix a bug where GET requests to /api/mcp were hanging indefinitely without sending an HTTP response. The GET handler has been replaced to return a 405 Method Not Allowed status with proper HTTP headers, conforming to the MCP Streamable HTTP transport specification.

Changes

Cohort / File(s)Summary
Changelog Documentation
CHANGELOG.md
Added entry in Unreleased section documenting the fix: GET requests to /api/mcp now return HTTP 405 Method Not Allowed instead of hanging.
Route Handler
packages/web/src/app/api/(server)/mcp/route.ts
Replaced GET handler implementation that was causing hangs. Old handler performed session validation and auth checks; new handler returns fixed 405 response with Allow: POST, DELETE header, removing all session lookup and authorization logic.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan-kellam/fix-SOU-827

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 470360d into mainMar 31, 2026
7 checks passed
@brendan-kellam
brendan-kellam deleted the brendan-kellam/fix-SOU-827 branch March 31, 2026 22:44
@github-actionsgithub-actionsBot mentioned this pull request Mar 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[bug] GET /api/mcp does not return HTTP response when valid session ID is provided (Streamable HTTP transport violation)

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(web): return 405 for GET /api/mcp instead of hanging connection - #1064

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan-kellam/fix-SOU-827
Mar 31, 2026
Merged

fix(web): return 405 for GET /api/mcp instead of hanging connection#1064
brendan-kellam merged 2 commits into
mainfrom
brendan-kellam/fix-SOU-827

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Mar 31, 2026

Copy link
Copy Markdown
Contributor

Summary

  • The GET /api/mcp handler opened an SSE stream that never flushed its HTTP response headers, causing clients to hang until timeout (0 bytes received)
  • Sourcebot does not send server-initiated messages, so the GET SSE stream serves no purpose
  • Per the MCP Streamable HTTP spec, servers that do not offer a GET SSE stream MUST return 405 Method Not Allowed

Fixes#1061

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes
    • Fixed an issue where the MCP API endpoint would hang when processing certain requests; it now properly returns a 405 Method Not Allowed response per the MCP Streamable HTTP specification.

The GET SSE stream is only used for server-initiated messages, which
Sourcebot does not send. Per the MCP Streamable HTTP spec, servers that
do not offer a GET SSE stream MUST return 405 Method Not Allowed.
Previously the handler opened an SSE stream that never flushed its HTTP
headers, causing clients to hang until timeout.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Mar 31, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 5a899a03-a11f-460e-9298-64f61b3dca1e

📥 Commits

Reviewing files that changed from the base of the PR and between f8e21d6 and 4920101.

📒 Files selected for processing (2)
  • CHANGELOG.md
  • packages/web/src/app/api/(server)/mcp/route.ts

Walkthrough

The changes fix a bug where GET requests to /api/mcp were hanging indefinitely without sending an HTTP response. The GET handler has been replaced to return a 405 Method Not Allowed status with proper HTTP headers, conforming to the MCP Streamable HTTP transport specification.

Changes

Cohort / File(s)Summary
Changelog Documentation
CHANGELOG.md
Added entry in Unreleased section documenting the fix: GET requests to /api/mcp now return HTTP 405 Method Not Allowed instead of hanging.
Route Handler
packages/web/src/app/api/(server)/mcp/route.ts
Replaced GET handler implementation that was causing hangs. Old handler performed session validation and auth checks; new handler returns fixed 405 response with Allow: POST, DELETE header, removing all session lookup and authorization logic.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan-kellam/fix-SOU-827

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 470360d into mainMar 31, 2026
7 checks passed
@brendan-kellam
brendan-kellam deleted the brendan-kellam/fix-SOU-827 branch March 31, 2026 22:44
@github-actionsgithub-actionsBot mentioned this pull request Mar 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[bug] GET /api/mcp does not return HTTP response when valid session ID is provided (Streamable HTTP transport violation)

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(web): return 405 for GET /api/mcp instead of hanging connection - #1064

Merged
brendan-kellam merged 2 commits into
mainfrom
brendan-kellam/fix-SOU-827
Mar 31, 2026
Merged

fix(web): return 405 for GET /api/mcp instead of hanging connection#1064
brendan-kellam merged 2 commits into
mainfrom
brendan-kellam/fix-SOU-827

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented Mar 31, 2026

Copy link
Copy Markdown
Contributor

Summary

  • The GET /api/mcp handler opened an SSE stream that never flushed its HTTP response headers, causing clients to hang until timeout (0 bytes received)
  • Sourcebot does not send server-initiated messages, so the GET SSE stream serves no purpose
  • Per the MCP Streamable HTTP spec, servers that do not offer a GET SSE stream MUST return 405 Method Not Allowed

Fixes#1061

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes
    • Fixed an issue where the MCP API endpoint would hang when processing certain requests; it now properly returns a 405 Method Not Allowed response per the MCP Streamable HTTP specification.

The GET SSE stream is only used for server-initiated messages, which
Sourcebot does not send. Per the MCP Streamable HTTP spec, servers that
do not offer a GET SSE stream MUST return 405 Method Not Allowed.
Previously the handler opened an SSE stream that never flushed its HTTP
headers, causing clients to hang until timeout.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented Mar 31, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 5a899a03-a11f-460e-9298-64f61b3dca1e

📥 Commits

Reviewing files that changed from the base of the PR and between f8e21d6 and 4920101.

📒 Files selected for processing (2)
  • CHANGELOG.md
  • packages/web/src/app/api/(server)/mcp/route.ts

Walkthrough

The changes fix a bug where GET requests to /api/mcp were hanging indefinitely without sending an HTTP response. The GET handler has been replaced to return a 405 Method Not Allowed status with proper HTTP headers, conforming to the MCP Streamable HTTP transport specification.

Changes

Cohort / File(s)Summary
Changelog Documentation
CHANGELOG.md
Added entry in Unreleased section documenting the fix: GET requests to /api/mcp now return HTTP 405 Method Not Allowed instead of hanging.
Route Handler
packages/web/src/app/api/(server)/mcp/route.ts
Replaced GET handler implementation that was causing hangs. Old handler performed session validation and auth checks; new handler returns fixed 405 response with Allow: POST, DELETE header, removing all session lookup and authorization logic.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan-kellam/fix-SOU-827

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@brendan-kellam
brendan-kellam merged commit 470360d into mainMar 31, 2026
7 checks passed
@brendan-kellam
brendan-kellam deleted the brendan-kellam/fix-SOU-827 branch March 31, 2026 22:44
@github-actionsgithub-actionsBot mentioned this pull request Mar 31, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[bug] GET /api/mcp does not return HTTP response when valid session ID is provided (Streamable HTTP transport violation)

1 participant

@brendan-kellam