Skip to content

Accept Codex standalone search input and output limits - #9750

Open
lpcox with Copilot wants to merge 2 commits into
mainfrom
copilot/api-proxy-fix-codex-search
Open

lpcox with Copilot wants to merge 2 commits into
mainfrom
copilot/api-proxy-fix-codex-search

Conversation

Copilot AI commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Codex 0.159.3 standalone search requests include max_output_tokens and often conversation input. The proxy rejects both as unknown fields, preventing search even when hosted-web policy permits it.

  • Request compatibility

    • Accept optional max_output_tokens as a non-negative integer.
    • Accept optional input as a string or array; preserve both fields when applying policy filters.
  • Policy boundaries

    • Retain filter intersection, query-domain narrowing, literal URL checks, unknown-command rejection, and standalone maxUses rejection.
    • Leave reasoning and additional command types unsupported.
  • Regression coverage

    • Cover realistic Codex payloads on both standalone endpoints, field preservation, and invalid shapes.

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix codex standalone search rejection due to body fields Accept Codex standalone search input and output limits Oct 9, 2026
Copilot AI requested a review from lpcox October 9, 2026 14:44
@lpcox
lpcox marked this pull request as ready for review October 9, 2026 15:55
Copilot AI balanced review requested due to automatic review settings October 9, 2026 15:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The focused compatibility change preserves existing security boundaries and includes adequate regression coverage.

0 open findings

What changed in this PR

Adds compatibility for Codex standalone hosted-search requests, resolving #9744 while retaining existing policy enforcement.

Changes:

  • Accepts and validates max_output_tokens and conversation input.
  • Preserves these fields while applying domain filters.
  • Adds regression coverage for both standalone endpoints and invalid values.
File Description
containers/​api-proxy/​codex-hosted-web.js Allows and validates the new standalone request fields.
containers/​api-proxy/​codex-hosted-web.test.js Covers preservation, validation, and endpoint routing.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

✅ Copilot review passed with no inline comments.

@copilot Add the ready-for-aw label to this PR to trigger agentic CI smoke tests.

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

✅ Coverage Check Passed

Overall Coverage

Metric Base PR Delta
Lines 93.04% 93.05% ➡️ +0.01%
Statements 91.56% 91.57% ➡️ +0.01%
Functions 90.23% 90.23% ➡️ +0.00%
Branches 85.29% 85.30% ➡️ +0.01%
📁 Per-file Coverage Changes (1 files)
File Lines (Before → After) Statements (Before → After)
src/log-directory-setup.ts 96.8% → 100.0% (+3.18%) 96.9% → 100.0% (+3.13%)

Coverage comparison generated by scripts/ci/compare-coverage.ts

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

api-proxy: codex standalone search is rejected because max_output_tokens and input are not allowed body fields

3 participants