1: <?php
2:
3: declare(strict_types=1);
4:
5: /**
6: * This file is part of the Nexus MCP SDK package.
7: *
8: * (c) 2026 John Paul E. Balandan, CPA <paulbalandan@gmail.com>
9: *
10: * For the full copyright and license information, please view
11: * the LICENSE file that was distributed with this source code.
12: */
13:
14: namespace Nexus\Mcp\Client\Exception;
15:
16: use Nexus\Mcp\Core\Exception\McpExceptionInterface;
17:
18: /**
19: * Thrown when a response arrived from a URL other than the one the request was sent to, which an HTTP client
20: * that follows redirects will do without re-checking the destination.
21: *
22: * @see https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization/security-considerations#communication-security
23: */
24: final class RedirectRefusedException extends \RuntimeException implements McpExceptionInterface
25: {
26: public function __construct(string $sent, string $answered)
27: {
28: parent::__construct(\sprintf(
29: 'The request to "%s" was answered from "%s" after a redirect. Credentials are never carried across one.',
30: $sent,
31: $answered,
32: ));
33: }
34: }
35: