Skip to content

fix(core-internal): percent-encode multi-variable URI template expansions - #2633

Open
nyxst4ck wants to merge 1 commit into
modelcontextprotocol:mainfrom
nyxst4ck:fix/uri-template-multi-variable-encoding
Open

fix(core-internal): percent-encode multi-variable URI template expansions#2633
nyxst4ck wants to merge 1 commit into
modelcontextprotocol:mainfrom
nyxst4ck:fix/uri-template-multi-variable-encoding

Conversation

@nyxst4ck

Copy link
Copy Markdown

Problem

UriTemplate.expand() encoded single-variable expressions but interpolated multi-variable expressions such as {x,y} without calling the encoder. For example:

new UriTemplate('{x,y}').expand({
  x: 'value with spaces',
  y: 'a/b?c&d'
})

returned value with spaces,a/b?c&d, which contains raw spaces and reserved characters where a simple expansion must percent-encode them.

Change

Route every value in the multi-variable branch through the same operator-aware encodeValue() helper used by single-variable expansions. This keeps reserved characters for reserved (+) expansions while encoding them for simple expansions.

The change is internal and focused, with no new public API. A patch changeset is included for the affected v2 packages.

Verification

  • pnpm --filter @modelcontextprotocol/core-internal test -- uriTemplate — 40 passed.
  • pnpm --filter @modelcontextprotocol/core-internal lint — passed, including Prettier check.
  • pnpm --filter @modelcontextprotocol/core-internal typecheck — passed.

The new tests cover both {x,y} and {+path,name}; they fail against the unpatched multi-variable branch and pass with this change.

…ions

UriTemplate.expandPart() interpolated the values of a multi-variable
expression raw, never calling encodeValue(). A template such as {x,y}
therefore emitted spaces and reserved characters verbatim, producing a
malformed URI, while the single-variable path encoded correctly.

Encode each value with the same operator-aware helper the single-variable
branch uses, so {x,y} percent-encodes reserved characters and {+x,y} /
{#x,y} keep them.
@nyxst4ck
nyxst4ck requested a review from a team as a code owner August 10, 2026 02:43
@changeset-bot

changeset-bot Bot commented Aug 10, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: cd1322c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
Name Type
@modelcontextprotocol/core-internal Patch
@modelcontextprotocol/client Patch
@modelcontextprotocol/server Patch
@modelcontextprotocol/core Patch
@modelcontextprotocol/server-legacy Patch
@modelcontextprotocol/codemod Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-new Bot commented Aug 10, 2026

Copy link
Copy Markdown

Open in StackBlitz

@modelcontextprotocol/client

npm i https://pkg.pr.new/@modelcontextprotocol/client@2633

@modelcontextprotocol/codemod

npm i https://pkg.pr.new/@modelcontextprotocol/codemod@2633

@modelcontextprotocol/core

npm i https://pkg.pr.new/@modelcontextprotocol/core@2633

@modelcontextprotocol/server

npm i https://pkg.pr.new/@modelcontextprotocol/server@2633

@modelcontextprotocol/server-legacy

npm i https://pkg.pr.new/@modelcontextprotocol/server-legacy@2633

@modelcontextprotocol/express

npm i https://pkg.pr.new/@modelcontextprotocol/express@2633

@modelcontextprotocol/fastify

npm i https://pkg.pr.new/@modelcontextprotocol/fastify@2633

@modelcontextprotocol/hono

npm i https://pkg.pr.new/@modelcontextprotocol/hono@2633

@modelcontextprotocol/node

npm i https://pkg.pr.new/@modelcontextprotocol/node@2633

commit: cd1322c

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant