Skip to content

Add scoped completion exchange service transport - #849

Open
tdurieux wants to merge 2 commits into
codex/review-completion-exchangefrom
codex/review-completion-http
Open

tdurieux wants to merge 2 commits into
codex/review-completion-exchangefrom
codex/review-completion-http

Conversation

@tdurieux

Copy link
Copy Markdown
Owner

Review needs authenticated completion exchange and receipt recovery without exposing these operations to browser sessions or capability-read credentials. This adds an optional HTTPS service handler with explicit completion.exchange and receipt.read scopes, strict bounded JSON, credential-window rechecks, request deadlines and concurrency/rate limits. It remains unmounted and unconfigured.

Validation: 17 transport tests pass, including rotation, incomplete uploads, duplicate keys, invalid UTF-8, scope separation and backend errors. The shared HTTPS client suite also passes. The full suite passes 754 cases with 73 environment-dependent cases pending; TypeScript, lint and frontend build pass. Fifty synthetic loopback HTTP receipt reads measured median 3.07 ms and p95 4.90 ms. A separate review-repository test uses the actual Go client and this TypeScript handler over verified TLS, covering replay, expiry recovery, policy mismatch, untrusted certificates and read-key rejection on exchange.

Stacks on #848. No startup mount, provider configuration, browser callback activation or deployment is included. Capabilities remain unavailable.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant