Skip to content

fix(codex): forward scoped canonical turn attribution - #28

Open
dannote wants to merge 1 commit into
masterfrom
feat/codex-turn-attribution
Open

dannote wants to merge 1 commit into
masterfrom
feat/codex-turn-attribution

Conversation

@dannote

@dannote dannote commented Sep 11, 2026

Copy link
Copy Markdown
Collaborator

Summary

Forward canonical Codex turn attribution from compatible Chat/Responses clients, extending the cache/session repair in #27.

  • Decode attribution headers, Responses client_metadata, and nested turn JSON through typed JSONCodec boundaries.
  • Reject conflicting copies, duplicate attribution headers, malformed/incomplete metadata, and invalid or oversized values with a safe HTTP 400 response.
  • Scope session, thread, turn, window, and installation identities consistently to the authenticated API key before forwarding. Preserve request kind, turn start time, and originator; keep explicit prompt-cache overrides separate.
  • Carry attribution through buffered and streaming Chat/Responses execution. Legacy requests do not acquire invented turn IDs.

Depends on agentjido/req_llm#1003. mix.exs and mix.lock pin its pushed commit, dannote/req_llm@856d65ea13728c1d2bd5046aac9143917e8cf7f8; there is no local-path dependency.

The client owns logical turn boundaries. This change repairs wire attribution; it does not establish a change in OpenAI's private quota accounting. Jido AI lifecycle integration, cross-request connection pooling, deployment, and broader JSONCodec migration are out of scope.

Validation

  • MIX_ENV=test mix ci passed against the exact Git dependency pin: 516 tests passed, 9 excluded; format, compilation, strict Credo, Dialyzer, duplication budget, and architecture checks passed.
  • Tests cover authenticated Chat/Responses ingress, buffered/streaming execution, all three upstream transport builders, key isolation, retained/rotated turn IDs, Unicode identity scoping, conflict rejection, safe errors, and legacy behavior.
  • ReqLLM's corresponding suite passes, including a local reused-WebSocket test checking attribution on each frame.
  • No live provider calls or deployment. Existing Cowlib advisories remain separate dependency-cleanup work.

Related

AI-assisted implementation and PR description.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant