fix(mcp): exclude OpenAPI header/cookie params from generated MCP tool schema

When an MCP server is generated from an OpenAPI spec, build_input_schema put
every operation parameter into the tool's input schema, including params with
in: header or in: cookie. The model was then asked to fill an auth header such
as an access token and it was passed as a tool function kwarg, which broke tool
invocation for services that require custom auth headers (LIT-1420).

Header and cookie params are HTTP-transport concerns: extract_parameters already
ignores them (only path/query/body reach the request), and header values are
forwarded from the MCP client's configured headers, not chosen by the model. So
they should never have been in the model-facing schema. This skips header/cookie
params in build_input_schema, matching extract_parameters.

Adds a regression test asserting a header and a cookie param are absent from the
generated schema while path, query, and body remain.
This commit is contained in:
mubashir1osmani 2026-07-24 00:19:43 -07:00
parent bd753aecf3
commit 13b5ce73b6
2 changed files with 33 additions and 0 deletions

View file

@ -261,6 +261,8 @@ def build_input_schema(operation: Dict[str, Any]) -> Dict[str, Any]:
for param in operation["parameters"]:
if "name" not in param:
continue
if param.get("in") in ("header", "cookie"):
continue
param_name = param["name"]
param_schema = param.get("schema", {})
param_type = param_schema.get("type", "string")

View file

@ -411,6 +411,37 @@ class TestBuildInputSchema:
# Required should include original names
assert "repository-id" in schema["required"]
def test_header_and_cookie_params_excluded(self):
"""Regression for LIT-1420: header/cookie OpenAPI params must not leak into
the MCP tool input schema. They are HTTP-transport concerns forwarded from
the MCP client's header config, not arguments the model should fill. Before
the fix, an auth header param was exposed as a tool arg and passed as a
function kwarg, breaking tool invocation."""
operation = {
"parameters": [
{"name": "orderId", "in": "path", "required": True, "schema": {"type": "string"}},
{"name": "expand", "in": "query", "required": False, "schema": {"type": "string"}},
{"name": "accessss-Token", "in": "header", "required": False, "schema": {"type": "string"}},
{"name": "session", "in": "cookie", "required": False, "schema": {"type": "string"}},
],
"requestBody": {
"content": {
"application/json": {
"schema": {"type": "object", "properties": {"note": {"type": "string"}}}
}
},
},
}
schema = build_input_schema(operation)
assert "accessss-Token" not in schema["properties"]
assert "session" not in schema["properties"]
assert "accessss-Token" not in schema["required"]
assert "orderId" in schema["properties"]
assert "expand" in schema["properties"]
assert "body" in schema["properties"]
class TestExtractParameters:
"""Test parameter extraction from OpenAPI operations."""