Skip to content

Conversation

@bokelley
Copy link
Contributor

Summary

  • Implements authoritative_location redirect following per the AdCP specification
  • When a publisher's adagents.json contains an authoritative_location field instead of authorized_agents, the function fetches the referenced URL to get the actual authorization data
  • Includes loop detection and max depth limit (5) for security
  • Validates HTTPS requirement for authoritative_location URLs

Test plan

  • Unit tests for happy path redirect following
  • Unit tests for HTTPS validation
  • Unit tests for circular redirect detection
  • Unit tests for max depth enforcement
  • All existing tests pass

Closes #114


Note: This PR also syncs main with maintenance/2.5 (50 commits) since maintenance/2.5 had drifted ahead.

🤖 Generated with Claude Code

bokelley and others added 2 commits January 26, 2026 06:46
Implements authoritative_location redirect following per the AdCP specification.
When a publisher's adagents.json contains an authoritative_location field
instead of authorized_agents, the function now fetches the referenced URL
to get the actual authorization data.

- Follows redirects with loop detection and max depth limit (5)
- Validates HTTPS requirement for authoritative_location URLs
- Handles edge case where both fields are present (authorized_agents takes precedence)
- Adds comprehensive tests for redirect scenarios

Closes #114

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Schema version 2.6.0 is not yet published on adcontextprotocol.org.
Downgrade to 2.5.3 (latest available) to unblock CI.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
bokelley added a commit that referenced this pull request Jan 26, 2026
- Implements authoritative_location redirect following per AdCP spec
- When adagents.json contains authoritative_location instead of
  authorized_agents, fetches the referenced URL for actual data
- Includes loop detection and max depth limit (5) for security
- Validates HTTPS requirement for authoritative_location URLs
- Tests for happy path, HTTPS validation, loop detection, max depth

Cherry-picked from PR #118 (bokelley/issue-114)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
bokelley added a commit that referenced this pull request Jan 26, 2026
#117)

* feat: add V3 protocol support (Governance, Content Standards, SI, CLI)

Add comprehensive V3 ADCP protocol support including:

Server Framework:
- Add GovernanceHandler for property list management
- Add ContentStandardsHandler for content calibration
- Add SponsoredIntelligenceHandler for conversational AI sponsorship
- Add governance method stubs to all protocol handlers
- Add MCP tool definitions for all V3 operations

Client:
- Add typed client methods for all V3 operations
- Export all V3 types from adcp.types

Protocol Adapters:
- Add governance methods to protocol base class
- Add governance implementations to MCP and A2A adapters

CLI:
- Add all V3 operations to command-line client:
  - Protocol Discovery: get_adcp_capabilities
  - Content Standards: 7 operations
  - Sponsored Intelligence: 4 operations
  - Governance: 5 operations

Types:
- Sync schemas with ADCP 2.6+ spec
- Generate types for V3 domains

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: resolve ruff linting errors

- Fix import block sorting (I001) across multiple files
- Remove unused import ContentStandards from content_standards.py
- Update Callable import to collections.abc in mcp_tools.py
- Fix line length (E501) in server/base.py

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* feat: sync with ADCP 2.6 schema changes

- Sync schemas from upstream adcontextprotocol.org
- Consolidate pricing options (CpmAuction/CpmFixed -> CpmPricingOption, VcpmAuction/VcpmFixed -> VcpmPricingOption)
- Consolidate PreviewRender (UrlPreviewRender/HtmlPreviewRender/BothPreviewRender -> unified PreviewRender)
- Update type exports and aliases for backwards compatibility
- Fix preview_cache.py to work with unified PreviewRender (no longer RootModel)
- Update tests to reflect schema changes

BREAKING CHANGE: CpmAuctionPricingOption, CpmFixedRatePricingOption, VcpmAuctionPricingOption, VcpmFixedRatePricingOption have been consolidated into CpmPricingOption and VcpmPricingOption respectively.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: resolve ruff import sorting error in _ergonomic.py

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* feat: sync schemas with upstream and fix type generation

- Fix generate_types.py to convert absolute /schemas/latest/ $ref paths
  to relative paths for proper schema resolution
- Sync all schemas from upstream (ADCP package 2.6)
- PreviewRender is now a discriminated union by output_format:
  - PreviewRender1 (output_format='url') with preview_url
  - PreviewRender2 (output_format='html') with preview_html
  - PreviewRender3 (output_format='both') with both
- Update aliases: UrlPreviewRender, HtmlPreviewRender, BothPreviewRender
  now point to their respective variant types
- Fix preview_cache.py to access RootModel.root for PreviewRender
- Update tests for discriminated union types

This fixes the "Validate schemas are up-to-date" CI failure.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* feat: support authoritative_location redirects in fetch_adagents

- Implements authoritative_location redirect following per AdCP spec
- When adagents.json contains authoritative_location instead of
  authorized_agents, fetches the referenced URL for actual data
- Includes loop detection and max depth limit (5) for security
- Validates HTTPS requirement for authoritative_location URLs
- Tests for happy path, HTTPS validation, loop detection, max depth

Cherry-picked from PR #118 (bokelley/issue-114)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: address PR review feedback for V3 migration

Handler Method Signatures:
- Refactored GovernanceHandler, ContentStandardsHandler, and
  SponsoredIntelligenceHandler to fix Liskov Substitution Principle violation
- Public methods now accept params: dict[str, Any] matching base class
- Added Pydantic validation with proper error responses
- Abstract handle_* methods accept typed requests for type safety

CLI Dispatch Table:
- Replaced mutable global TOOL_DISPATCH with cached _get_dispatch_table()
- Fails fast with clear error message if types can't be imported
- Eliminates late import error surprises

Version Interop Tests:
- Added test_version_interop.py to verify V3/V2 compatibility
- Tests V3-only tools are in dispatch table
- Tests V2 core tools remain available
- Tests base handler returns 'not supported' for unimplemented V3 methods

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: rename summary() to model_summary() to avoid field collision

The generated POC types have `summary` fields that conflicted with
the AdCPBaseModel.summary() method, causing mypy errors. Renamed
to model_summary() to follow Pydantic's naming convention
(model_dump, model_dump_json, etc.) and avoid the collision.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* docs: add tests documenting version negotiation design

Version negotiation is intentionally delegated to consumers. The SDK
provides primitives (get_adcp_capabilities, TaskResult wrapping), not
policy. Added TestVersionNegotiationDesign class with tests that serve
as executable documentation for:

- TaskResult error wrapping pattern
- Capabilities response structure
- Recommended version detection pattern
- Recommended feature detection pattern

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* docs: update pricing option examples to current schema format

Updated test fixtures and documentation examples from deprecated format:
  {"model": "cpm_fixed_rate", "is_fixed": true, "cpm": 5.50}

To current unified CpmPricingOption schema format:
  {
    "pricing_model": "cpm",
    "pricing_option_id": "po-1",
    "currency": "USD",
    "fixed_price": 5.50
  }

The old format used separate types with is_fixed discriminator.
The new schema uses optional fixed_price/floor_price fields to
distinguish fixed vs auction pricing.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* feat: upgrade to ADCP 3.0.0-beta.1 schemas

- Update ADCP_VERSION from 'latest' to '3.0.0-beta.1'
- Sync schemas from https://adcontextprotocol.org/schemas/3.0.0-beta.1/
- Update generate_types.py to handle versioned schema paths
  (previously only handled /schemas/latest/, now handles /schemas/<version>/)
- Regenerate Pydantic models from new schemas
- All 518 tests pass
- mypy passes with no issues

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* style: fix import sorting in _ergonomic.py

Reorder imports to satisfy ruff I001 (isort) rules.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* ci: skip schema sync for pre-release versions

Pre-release schema versions (alpha, beta, rc) may not be publicly
accessible from CI environments. Skip the download/sync steps for
these versions and rely on committed schemas instead.

Validation steps (syntax check, import test, code generation tests)
still run to ensure the committed schemas work correctly.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
@bokelley bokelley closed this Jan 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug : fetch_adagents does not follow authoritative_location redirects per AdCP specification

2 participants