Skip to content

Support explicit provider model catalog URLs - #46561

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/7f6ac5eec257278685e1867a6bcebae6514a365a
Sep 19, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/7f6ac5eec257278685e1867a6bcebae6514a365a

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Support explicit provider model catalog URLs

Why

Providers need to serve Codex model metadata independently of their inference endpoint. A custom inference base_url alone should not opt API-key sessions into remote catalog discovery.

What changed

  • Add model_catalog_url to provider configuration and thread-config serialization. Fetch the full catalog URL with provider authentication, headers, query parameters, and client_version, while preserving inference routing.
  • Require an explicit catalog URL for API-key discovery with a custom base URL. Keep default OpenAI discovery on the Codex backend, and apply api_key_model_discovery gating to provider API keys and cached catalogs.
  • Include the catalog URL in cache identity so different catalogs do not share cached metadata.
  • Limit explicitly configured catalog responses to 1 MiB, reject redirects, and suppress URL and response diagnostics that could expose credentials.

Testing

Add coverage for catalog configuration round-trips, query encoding, authentication and header reuse, cache identity and discovery gating, oversized responses, and redirect rejection without credential forwarding. Add an integration test verifying that catalog model metadata and instructions reach conversation requests.

## Why

Providers need to serve Codex model metadata independently of their inference endpoint. A custom inference `base_url` alone should not opt API-key sessions into remote catalog discovery.

## What changed

- Add `model_catalog_url` to provider configuration and thread-config serialization. Fetch the full catalog URL with provider authentication, headers, query parameters, and `client_version`, while preserving inference routing.
- Require an explicit catalog URL for API-key discovery with a custom base URL. Keep default OpenAI discovery on the Codex backend, and apply `api_key_model_discovery` gating to provider API keys and cached catalogs.
- Include the catalog URL in cache identity so different catalogs do not share cached metadata.
- Limit explicitly configured catalog responses to 1 MiB, reject redirects, and suppress URL and response diagnostics that could expose credentials.

## Testing

Add coverage for catalog configuration round-trips, query encoding, authentication and header reuse, cache identity and discovery gating, oversized responses, and redirect rejection without credential forwarding. Add an integration test verifying that catalog model metadata and instructions reach conversation requests.

GitOrigin-RevId: 7f6ac5eec257278685e1867a6bcebae6514a365a
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/7f6ac5eec257278685e1867a6bcebae6514a365a branch from c81f631 to 888be42 Compare September 19, 2026 01:37
@github-actions

Copy link
Copy Markdown
Contributor


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@copyberry
copyberry Bot merged commit 888be42 into main Sep 19, 2026
10 of 17 checks passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/7f6ac5eec257278685e1867a6bcebae6514a365a branch September 19, 2026 01:37
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 19, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant