Skip to content

📔 feat: Preserve Owner Text During PII Redaction - #16311

Open
lia-by-librechat[bot] wants to merge 10 commits into
devfrom
lia/pii-owner-view
Open

lia-by-librechat[bot] wants to merge 10 commits into
devfrom
lia/pii-owner-view

Conversation

@lia-by-librechat

@lia-by-librechat lia-by-librechat Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Summary

With filters.messages.pii.action: redact, fresh text-only interactive Agent chat submissions now continue with a filtered model-facing copy. The owner can still read the submitted original after reload. Other ingress and unsupported submission shapes retain the existing blocking behavior. The default action is unchanged.

The filtered text is canonical in request execution, message storage, ordinary message reads, sharing, and exports. Originals use a separately authorized display endpoint and React context, not the ordinary message/query cache, edit callbacks, or prompt history. Browser request diagnostics now log identifiers rather than submitted text.

How it works

interactive text -> bounded PII transform -> namespaced placeholders -> existing checks
               \-> encrypted request capture -> final message identity
                                                   |
                          one atomic MongoDB write: filtered text + encrypted private sidecar
                                                   |
                            await persistence before main provider invocation

owner-only batch read -> authenticate + tenant/owner query -> verify AES-GCM binding
                     -> display-only context -> original text + privacy indicator
ordinary reads / share / exports -> filtered text only

The sidecar is a select: false, unindexed field on the message, rather than a separate collection. This keeps canonical text and the encrypted original atomic and gives them the same deletion/TTL lifecycle, without orphan cleanup. AES-GCM authenticates the owner, tenant, conversation, message, revision, and canonical text. The key is derived from CREDS_KEY with domain separation. Keyed, submission-specific revisions preserve network-retry identity and prevent unrelated placeholders from aliasing across history.

The owner endpoint batches up to 50 IDs, returns Cache-Control: private, no-store, and never grants original access from sharing or administrator status. It loads up to three batches concurrently and reuses only unchanged owner-, tenant-, conversation-, revision- and text-matched originals. A missing result while a turn is still being persisted is retried once when submission settles; failures and unavailable originals retain a localized manual retry action. Missing keys, tampering, stale rows, and decryption failures fall back to filtered text. Persistence failure prevents the main provider call.

Every text-bearing Agent chat POST loads the configured policy before early ban denial; only supported fresh interactive turns are transformed. Denials with matching untransformed text or missing policy fail closed before emitting or saving it. Protected Stop carries the nonsecret revision through preliminary and created-event job metadata to the abort final event; it verifies the existing sidecar without rewriting it. For older revisionless job records, the ordinary prerequisite is insert-only and cannot overwrite an existing protected row; identified filtered placeholders require an existing protected row. Canonical edits atomically discard stale private fields; imports, forks, and bulk copies cannot transplant private fields to new identities. Browser diagnostics project only identifiers.

Scope and rollout

  • Opt-in: configure the redact action with selected text patterns and retain a valid CREDS_KEY.
  • Supported here: fresh text-only interactive Agent-route submissions, ordinary owner reload, network retries, and filtered sharing.
  • Not enabled here: default-on policy, files/quotes, edits/regenerations/resumes, alternate ingress, bound-secret redaction, background-tool filtering, or historical migration.
  • Key rotation caveat: this slice does not retain a previous-key ring. Changing or losing CREDS_KEY makes existing originals unavailable. Preserve the key with encrypted backups. Canonical filtered messages remain usable.
  • Rollback to block stops transformation without restoring raw text into canonical storage. Older clients can still read filtered messages. This does not retroactively remove PII from historical records or infrastructure body capture.

Type of change

  • Feature
  • Tests

Testing

  • Focused checks: 49 Agent-route/denial/Stop tests, 43 ban-middleware tests, 137 package API private-text/job-store tests, 11 Mongo-backed protected-message tests, 14 owner-view UI tests, 4 partial-disconnect controller tests, 2 focused resume-metadata controller tests, and 48 tenant stream/Stop tests. Earlier merged-head regression suites remain in CI.
  • Real MongoDB tests: atomic storage, hidden ordinary projections, owner and tenant isolation, untrusted write fields, expiration, and deletion.
  • Current-head browser test with the real mock-provider adapter passed: exact model input is filtered, original reload works, network retry preserves the conversation, sharing is filtered, ciphertext is stored, unauthorized retrieval fails, and deletion removes the row. Light/dark screenshots were captured locally. GitHub media upload rejected the GitHub App authentication type, so they are not attached.
  • Typechecks in packages/api, packages/data-schemas, packages/data-provider, and client; package builds and touched-file static checks.
  • Lighthouse was attempted before and after UI changes. The pre-change audit could not launch full Chromium in this sandbox; a later headless-shell run exceeded the 90-second command limit. No local Lighthouse performance result is claimed. The exact current head passed Lighthouse CI and every other required CI check. Local Lighthouse was attempted on this branch but could not connect to sandbox Chrome; no local performance result is claimed. The browser flow itself runs successfully with workspace-local Chromium libraries and MongoDB configured without Unix sockets.

Subsystem self-review covered the early ingress boundary, ban and message-limit denial, Stop persistence, ordinary and fallback user-message writers, retry identity, owner/tenant authorization, canonical and shared readers, display/cache isolation, expiration/deletion, key loss, and rollback. Codex reviewed the earlier 27bd2242a1 head; its three newly reported lifecycle findings are addressed on the pushed head 22734756b2, which awaits independent review.

Screenshots

The owner view shows the original while canonical storage and sharing retain typed placeholders. The test also verifies reload and captures light and dark mode. Files remain in the worktree under e2e/specs/.test-results/private-text-*/owner-text-{light,dark}.png; no uploaded image is claimed.

Title verification: 📔 has 1 prior subject-leading use in 5,540 indexed LibreChat commits through 2026-09-23 23:08:36. The earlier use was a hosting guide, not the owner-original frame; the sentinel passed.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review handoff for exact remote head 7117f1d40c016fbe5bdc370221806d95ce28ec52.

PR 2 adds opt-in text-only interactive redaction, atomic canonical text plus encrypted owner sidecar storage, a tenant/owner-authorized batch view, and a display-only UI context. Normal history, sharing, exports, request execution, and diagnostics do not receive the original. The browser test inspects the actual mock-provider message projection, then exercises owner reload, network retry, sharing, unauthorized retrieval, ciphertext storage, and deletion.

Verification: 681 focused tests passed (139 API, 142 data-schemas, 14 filter-schema, 74 client, 312 legacy/controller); the final browser test passed; all four changed TypeScript workspace checks, package builds, and staged static checks passed. The synthetic PII canary was absent from the successful browser-run server log.

Invariant self-review covered ingress ordering, initial and fallback writers, persistence failure/admission, retry identity, tenant and owner isolation, canonical/share readers, display-cache invalidation, expiry/deletion, and rollback. No independent review has arrived for this head yet.

Explicit limits: the default is unchanged; non-text and alternate ingress retain blocking; no historical migration or bound-secret protection is enabled here. The sidecar shares message deletion/retention. CREDS_KEY rotation without retaining the old key makes prior originals unreadable; canonical filtered content remains usable.

Local Lighthouse was attempted before and after UI changes but did not produce a passing result: the initial full-browser launch lacked system libraries and the later audit exceeded the 90-second tool budget. No performance score is claimed. Light/dark screenshots were captured, but GitHub media upload rejected App authentication and they are not attached. CI and fresh review still need to cover this SHA.

@github-actions

Copy link
Copy Markdown
Contributor

Lighthouse CI failed. The last 80 log lines contain the measured budgets and assertion failures.

│ 21      │ 'http://localhost:3080/api/convos?pinned=true&limit=100'                                                        │ 2719.539999999979  │ 3477.017999999982  │ 200    │
│ 22      │ 'http://localhost:3080/api/mcp/servers'                                                                         │ 3049.9229999999807 │ 4313.694999999978  │ 200    │
│ 23      │ 'http://localhost:3080/api/permissions/mcpServer/effective/all'                                                 │ 3051.25999999998   │ 3810.5049999999756 │ 200    │
│ 24      │ 'http://localhost:3080/api/prompts/groups?limit=10'                                                             │ 3051.5409999999683 │ 4325.273999999976  │ 200    │
│ 25      │ 'http://localhost:3080/api/keys?name=openAI'                                                                    │ 3275.359999999957  │ 3986.109999999986  │ 200    │
│ 26      │ 'http://localhost:3080/api/presets'                                                                             │ 3277.0229999999865 │ 3986.356999999989  │ 200    │
│ 27      │ 'http://localhost:3080/api/tags'                                                                                │ 3277.2849999999744 │ 3991.1199999999953 │ 200    │
│ 28      │ 'http://localhost:3080/api/share/link/16390000-0000-4000-8000-000000000001'                                     │ 3277.508999999962  │ 4315.609999999986  │ 200    │
│ 29      │ 'http://localhost:3080/api/messages/16390000-0000-4000-8000-000000000001'                                       │ 3277.6789999999746 │ 4495.280999999959  │ 200    │
│ 30      │ 'http://localhost:3080/api/files/config'                                                                        │ 3278.92399999997   │ 4244.030999999959  │ 200    │
│ 31      │ 'http://localhost:3080/api/agents/tools/web_search/auth'                                                        │ 3279.1419999999634 │ 7012.731           │ 200    │
│ 32      │ 'http://localhost:3080/api/endpoints/token-config'                                                              │ 3280.0049999999756 │ 4501.006999999983  │ 200    │
│ 33      │ 'http://localhost:3080/api/agents/tools/calls?conversationId=16390000-0000-4000-8000-000000000001'              │ 3280.2369999999937 │ 4821.611999999965  │ 200    │
│ 34      │ 'http://localhost:3080/api/agents/chat/status/16390000-0000-4000-8000-000000000001?generationProtocolVersion=2' │ 4588.020999999979  │ 4843.293999999965  │ 200    │
└─────────┴─────────────────────────────────────────────────────────────────────────────────────────────────────────────────┴────────────────────┴────────────────────┴────────┘

Inspect .lighthouse HTML/JSON and e2e/lighthouse/README.md. Reuse loaded user/config data; overlap independent reads without bypassing authorization.

┌─────────┬────────────────────────────┬──────────────────────┬───────┐
│ (index) │ audit                      │ median               │ limit │
├─────────┼────────────────────────────┼──────────────────────┼───────┤
│ 0       │ 'largest-contentful-paint' │ 4537.837             │ 4500  │
│ 1       │ 'cumulative-layout-shift'  │ 0.016891882223535586 │ 0.1   │
│ 2       │ 'total-blocking-time'      │ 203.86200000000008   │ 500   │
└─────────┴────────────────────────────┴──────────────────────┴───────┘

  1) [chrome] › e2e/lighthouse/load.spec.ts:10:5 › serial database latency stays within web-vitals budgets 

    Error: Median largest-contentful-paint must stay within 4500

    expect(received).toBeLessThanOrEqual(expected)

    Expected: <= 4500
    Received:    4537.837

       at audit.ts:159

      157 |   console.table(measured);
      158 |   for (const { audit, median, limit } of measured) {
    > 159 |     expect(median, `Median ${audit} must stay within ${limit}`).toBeLessThanOrEqual(limit);
          |                                                                 ^
      160 |   }
      161 |   return results;
      162 | }
        at auditPage (/home/runner/work/LibreChat/LibreChat/e2e/lighthouse/audit.ts:159:65)
        at /home/runner/work/LibreChat/LibreChat/e2e/lighthouse/load.spec.ts:33:19

    attachment #1: screenshot (image/png) ──────────────────────────────────────────────────────────
    e2e/lighthouse/.test-results/load-serial-database-latency-stays-within-web-vitals-budgets-chrome/test-failed-1.png
    ────────────────────────────────────────────────────────────────────────────────────────────────

    Error Context: e2e/lighthouse/.test-results/load-serial-database-latency-stays-within-web-vitals-budgets-chrome/error-context.md

    attachment #3: trace (application/zip) ─────────────────────────────────────────────────────────
    e2e/lighthouse/.test-results/load-serial-database-latency-stays-within-web-vitals-budgets-chrome/trace.zip
    Usage:

        npx playwright show-trace e2e/lighthouse/.test-results/load-serial-database-latency-stays-within-web-vitals-budgets-chrome/trace.zip

    ────────────────────────────────────────────────────────────────────────────────────────────────


🤖: global teardown has been started
2026-09-24 13:33:03 �[32minfo�[39m: �[32mMongo Connection options�[39m
2026-09-24 13:33:03 �[32minfo�[39m: �[32m{�[39m
�[32m  "bufferCommands": false�[39m
�[32m}�[39m
🤖:  ✅  Connected to Database
🤖:  ✅  Found user in Database
🤖:  ✅  Deleted 1 convos & 2 messages
🤖:  ✅  Deleted user from Database
🤖: global teardown has been started
2026-09-24 13:33:03 �[32minfo�[39m: �[32mMongo Connection options�[39m
2026-09-24 13:33:03 �[32minfo�[39m: �[32m{�[39m
�[32m  "bufferCommands": false�[39m
�[32m}�[39m
🤖:  ✅  Connected to Database
🤖:  ⚠️  User not found in Database
  1 failed
    [chrome] › e2e/lighthouse/load.spec.ts:10:5 › serial database latency stays within web-vitals budgets 

Open the full run

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review handoff for exact remote head 5634f3fa082f141a32ccabd53db81cc071ab3d5a. CI repair: route tests now provide the new private-text view/ingress factories; ordinary conversations bypass the owner-only provider, avoiding auth-context work and fetch setup on the Lighthouse transcript. New regression test covers the no-private-text fast path. Local verification: seven affected API suites (59 tests), two client suites (11 tests), client TypeScript, client production build, and staged static checks passed. Protected owner-view browser recheck and CI for this head are pending. No inline review threads were present on the previous head.

@danny-avila

Copy link
Copy Markdown
Collaborator

@codex review the latest head

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T14:54:31.593933Z 2273475 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5634f3fa08

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/data-schemas/src/schema/message.ts
Comment thread client/src/components/Chat/Messages/PrivateText.tsx Outdated
Comment thread packages/data-schemas/src/methods/message.ts
Comment thread client/src/components/Chat/Messages/PrivateText.tsx Outdated
@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review handoff for exact remote head 28ed3d1ea83c8fc29d498f43c21f8b5aa9894ac8. All four actionable Codex threads were fixed and replied to with this commit: imported/bulk/fork sidecar sanitation, bounded concurrent incremental owner fetches with scoped revision reuse, atomic stale-ciphertext removal on canonical edits (and local revision invalidation), and normal user-message presentation for display-only originals.\n\nFocused checks passed: 149 Mongo-backed schema tests and data-schemas TypeScript/build; 27 client edit, protected display, and ordinary-chat tests plus client TypeScript/build; 288 fork/import/agent-controller tests; the protected browser submit/retry/reload/share/deletion flow, including a normal dir=auto container; the real API build; and staged static checks. The previous PR head was green across all 31 non-skipped CI checks. CI including Lighthouse for this new head is pending; I did not rerun local Lighthouse. The final browser test passed against the current UI and a schema build with identical runtime behavior prior to the ES2019-compatible null-edit check. No independent review has arrived for this new head yet.

@danny-avila

Copy link
Copy Markdown
Collaborator

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 28ed3d1ea8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread api/server/routes/agents/chat.js Outdated
Comment thread packages/data-schemas/src/methods/message.ts
Comment thread client/src/components/Chat/Messages/PrivateText.tsx
Comment thread client/src/hooks/Chat/useChatFunctions.ts
@danny-avila danny-avila added 🗺️ Moderation Sec codegraph: the taxonomy area this belongs to (classifier, confidence ≥ 0.9) 🛡️ security review labels Sep 25, 2026
# Conflicts:
#	api/server/controllers/agents/__tests__/request.partialDisconnect.spec.js
#	api/server/controllers/agents/__tests__/request.resumeMetadata.spec.js
#	client/src/locales/en/translation.json
@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review handoff for exact remote head 27bd2242a1f4b9ff09296214136e4e9cbdc35a88. Brought the branch up to 696ebedce04c7804dcf18920c654cfa173d2ec80 (origin/dev at merge time), resolving three conflicts without rewriting the reviewed commits. This head fixes Codex's four actionable findings: filters before ban/limit denials with a safe unsupported-content fallback and encrypted denial persistence; Stop verifies the already-persisted sidecar instead of destroying it; owner-view failures have an explicit localized retry; browser submission diagnostics log identifiers only. Focused JS tests (255), Mongo message tests (172), PII transformer tests (31), UI tests (28), all changed TS workspaces' typechecks, backend and frontend builds, staged static checks, and the protected browser submit/retry/reload/share/delete flow passed locally. PR-wide static and CI including Lighthouse are running on this exact SHA. No review of this SHA has arrived yet.

@danny-avila

Copy link
Copy Markdown
Collaborator

@codex review the latest head

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 27bd2242a1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread api/server/routes/agents/index.js Outdated
Comment thread api/server/routes/agents/index.js
Comment thread client/src/components/Chat/Messages/PrivateText.tsx
@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Exact-head review handoff: a036847b15ee623efb0d2a04cb9a4c954c9d9c98. This head loads policy before text-bearing Agent ban denials (including queued turns), carries the private revision from preliminary and created job metadata through Stop, preserves older revisionless rows through insert-only storage, and retries early missing owner reads once after turn completion. Focused Agent-route, ban, Mongo, job-store and UI tests passed; changed-workspace TypeScript, builds, PR-wide static checks, and a real-browser protected conversation passed. Please review this exact SHA; previous-head review findings are answered on their threads.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

New exact-head review handoff: 0cf0686ec6c426cbafe52842c89e38eaf8b61831. The protected-message lifecycle fix remains on this head. This follow-up only teaches the partial-disconnect controller test its new preliminary metadata pass-through and formats the new job-store regression for CI. The formerly failing partial-disconnect suite (4/4) and current-dev PR-wide static checks pass locally. Please review this exact SHA; earlier reviews covered previous heads.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Exact-head review handoff: 7696f792b40d2a643dfe7bb7fd337c7f80af2630. The opt-in protected-message fixes remain unchanged. This final follow-up completes the legacy partial mock in the 160-case resume-metadata controller suite. Its two focused early-job cases pass, as do the 4 partial-disconnect tests, current-dev PR-wide static checks, package API TypeScript, protected-message Mongo/job-store/route/UI suites, and the focused real-browser flow. CI is rerunning against this head; please assess this exact SHA rather than earlier heads.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Exact-head review handoff: 22734756b250eb9aad664dd2dcf1a64658163f71. CI uncovered a tenant Stop test stub that returned a flag instead of the saved message identity. The fixture now returns the persisted identity and asserts the insert-only Stop prerequisite. All 48 tenant stream/Stop tests and PR-wide static checks pass locally. The production protection flow is unchanged from the previous head; CI and independent review must assess this exact SHA.

@danny-avila

Copy link
Copy Markdown
Collaborator

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 22734756b2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines 53 to +54
if (shouldSaveMessage) {
await saveMessage(
await savePrivateTextMessage(

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve owner text for denied first turns

When a PII-containing first turn is rejected by checkBan or a message limiter, the client sends no conversation ID and uses NO_PARENT, so shouldSaveMessage is false and this protected save is skipped. The preceding created event nevertheless replaces the client's optimistic plaintext with the canonical text and privacyRevision; OwnerTextProvider then queries a sidecar that was never stored and permanently displays “Original unavailable,” including after Retry. Preserve the owner view for this unsaved failure path or avoid stamping an unrecoverable revision.

AGENTS.md reference: AGENTS.md:L42-L44

Useful? React with 👍 / 👎.

Comment on lines +230 to +233
const text = result.content.replace(
/\[(EMAIL|PHONE|NAME|CREDENTIAL|CUSTOM)_(\d+)\]/g,
(marker, category: string, index: string) =>
body.text.includes(marker) ? marker : `[${category}_${index}_${revision}]`,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Exempt generated placeholders from the second PII pass

When the redact policy includes a custom pattern that matches the generated 32-character hexadecimal revision (for example, a credential rule matching [a-f0-9]{32}), this suffix introduces a new PII match that was not present in the submitted text. The normal chat middleware at api/server/routes/agents/chat.js:75-80 subsequently inspects the transformed body again, treats the redact finding as blocking, and rejects an otherwise supported submission with a content-filter error. Mark captured text as already transformed or prevent the downstream inspector from evaluating the generated placeholders.

AGENTS.md reference: AGENTS.md:L42-L44

Useful? React with 👍 / 👎.

Comment on lines +191 to +194
<OwnerTextProvider
messages={messages}
conversationId={conversationId}
isSubmitting={chatHelpers.isSubmitting}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Query owner text with the resolved first-turn ID

During a successful first turn, this prop is still the route value new; the created event has already replaced the optimistic message with a protected message whose own conversationId is the newly allocated UUID, but navigation to that UUID occurs only in the final handler. The provider therefore posts to /api/messages/new/owner-text, which the UUID validation rejects, and shows “Original unavailable” for the entire model generation even though the sidecar is persisted before the provider call. Resolve the owner-text scope from the acknowledged message/conversation ID so the original can load while the first response is streaming.

AGENTS.md reference: AGENTS.md:L42-L44

Useful? React with 👍 / 👎.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🗺️ Moderation Sec codegraph: the taxonomy area this belongs to (classifier, confidence ≥ 0.9) 🛡️ security review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants