Optional Plug binding for the stateless Streamable HTTP adapter.
The application supplies an immutable :runtime and a supervised :executor.
This Plug starts no listener or global runtime. Install it before body parsers,
after the application's authentication Plug. Only conn.assigns[:mcp_auth]
supplies Snodo.Context.auth; request headers and JSON never supply identity.
Requests are admitted before entering the bounded executor. Valid cancellation
notifications bypass that queue. Cross-request cancellation is opt-in through
the trusted :mcp_cancellation_scope assign, combined with the complete auth
value; applications must distinguish authenticated client instances in this
scope. Anonymous requests cannot cancel each other by guessing request IDs.
Portable Plug APIs only reveal a disconnect when a write fails. So that a
client disconnect cancels a silent handler, as the 2026-07-28 cancellation
rules require, a request still running after :disconnect_probe_ms (default
5,000) turns its response into an event stream and sends a keepalive comment
every interval; a failed write cancels the work, and the result arrives as
the stream's final event. :infinity keeps plain JSON responses. A finite
total :request_timeout bounds pending work and queue wait.