ragleap-integrations · release notes
2026-10-06 · ragleap-integrations-v0.1.0
ragleap-integrations v0.1.0
Added
- An MCP client over Streamable HTTP that returns ragleap_tools.Tool objects (McpConfig, McpServerConfig, McpToolSpec, McpClient, make_mcp_tools). Owner-configured servers and an exact server.tool allowlist; nothing is read from the environment; tools are discovered once (a snapshot) or supplied as specs, in which case nothing is sent over the network at setup.
- Modern (2026-07-28) requests with Mcp-Method, Mcp-Name and Mcp-Param-* headers and params._meta; legacy servers are detected per the specification's backward-compatibility rules and spoken to with the initialize handshake for 2025-06-18 only.
- A bounded, stdlib-only HTTPS transport: public-address check with the connection pinned to the resolved IP, TLS (minimum 1.2) verified against the hostname, no redirects, response-size cap, constant error messages, and a watchdog-enforced wall-clock deadline.
Verified
- 201 tests, including a real local TLS server; CI green on Python 3.10, 3.11 and 3.12. After release, the published wheel and sdist were checked: the installed files are byte-identical to the tested ones and the sdist's tests pass against the installed wheel.
- Live-checked on 2026-10-05 against DeepWiki's public MCP server (no authentication): the server rejected the modern request with HTTP 400 and -32600, the client fell back to the legacy handshake (2025-06-18), listed tools and read a repository's documentation structure. The live check found and fixed a legacy-detection bug before release.
Not verified
- The modern 2026-07-28 path against a real server, x-mcp-header mirroring, where a -32022 error carries its supported-version list, bearer-token authentication, plain JSON (non-stream) responses and pagination.
Known limitations
- On a legacy server every call performs a full initialize handshake and never closes the session. HeaderMismatch is not retried. Only text content is returned. Server-supplied text (descriptions, schemas, results) is untrusted and not screened for prompt injection.
Release notes mirrored from GitHub Releases.