Skip to content

fix(cline): preserve only client-supplied task IDs - #10279

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.50from
arafatkatze:arafatkatze/fix-cline-generated-task-id
Aug 21, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.50from
arafatkatze:arafatkatze/fix-cline-generated-task-id

Conversation

@arafatkatze

Copy link
Copy Markdown
Contributor

What changed

  • forward a sanitized inbound X-Task-ID for Cline and ClinePass requests
  • omit X-Task-ID when the client did not supply one
  • remove configured/stored task headers so proxy configuration cannot invent task identity
  • add unit coverage for passthrough, omission, and configured-header removal
  • add a full chat-pipeline regression test covering ClinePass routing and upstream headers

Why

OmniRoute currently falls back to randomUUID() when a client does not send X-Task-ID. Because the fallback is generated once per upstream request, downstream systems can mistake independent requests for durable client tasks.

The proxy cannot infer a real task boundary for arbitrary clients. Preserving a client-provided ID and otherwise omitting the optional header keeps task identity truthful.

Impact

  • clients that provide a task ID keep the existing behavior
  • clients without a task ID no longer emit fabricated request-scoped task identities
  • Cline/ClinePass authentication and the remaining protocol headers are unchanged

Validation

  • pre-fix controlled pipeline reproduction: two requests without an inbound task ID emitted different UUIDs; an inbound client-task-123 value was preserved
  • post-fix focused unit + full-pipeline tests: 13/13 unit tests and 1/1 integration test passed
  • npm run typecheck:core
  • focused ESLint on all changed TypeScript files
  • npm run check:changelog-integrity

The integration test exercises the complete request handler, provider routing, authentication-header construction, executor, and mocked upstream boundary without using a live account or incurring model usage.

Base status

⚠️ base-red inherited: #9985

Full-repository npm run lint also reaches two unrelated errors already present outside this diff (@omniroute/opencode-plugin/src/index.ts:5481 and tests/unit/cli-env-inline-comment-10100.test.ts:35). Focused lint for every changed TypeScript file passes.

Test files

  • tests/unit/cline-workos-auth-token-shape.test.ts
  • tests/integration/cline-task-id-propagation.test.ts

@arafatkatze
arafatkatze marked this pull request as ready for review August 13, 2026 18:19
@arafatkatze

Copy link
Copy Markdown
Contributor Author

@diegosouzapw This is Ara from the Cline team .

This PR will fix task-id joining issues on our end can you please merge this trivial fix?

@diegosouzapw

Copy link
Copy Markdown
Owner

Deferido para revalidação do head atual. A rodada anterior registrou um hold de ownership, mas a inspeção atual não confirmou esse worktree; por favor, reconfirme o head e os checks antes da decisão final.

@diegosouzapw diegosouzapw added deferred-v3.8.50 Adiada para o ciclo v3.8.50 (validacao VPS, refactor, ou escopo grande) merge-train-deferred PR ejetada do merge-train — triagem separada and removed merge-train-deferred PR ejetada do merge-train — triagem separada deferred-v3.8.50 Adiada para o ciclo v3.8.50 (validacao VPS, refactor, ou escopo grande) labels Aug 17, 2026
@arafatkatze
arafatkatze force-pushed the arafatkatze/fix-cline-generated-task-id branch from 342b4c3 to 2e47413 Compare August 17, 2026 23:33
@arafatkatze

Copy link
Copy Markdown
Contributor Author

Revalidei o head atual e atualizei a branch.

  • base atual: release/v3.8.50 @ aa912c42a7d50dd4c87c356f42218ccd2ff42c59
  • head atual: 2e47413986d7d68ffe4c12c64ea224173748bd52
  • rebase concluído sem conflitos; o escopo continua restrito ao passthrough/omissão de X-Task-ID
  • unitário focado: 12/12 passando
  • integração end-to-end local: 1/1 passando pelo pipeline completo POST /v1/chat/completions -> routing/executor -> upstream mock; confirma que IDs ausentes continuam ausentes e um ID enviado pelo cliente é preservado
  • ESLint focado: passando
  • Prettier: passando
  • changelog integrity: passando contra upstream/release/v3.8.50
  • Semgrep do PR: passando
  • Mergify: concluído como neutral/skipped

npm run typecheck:core ainda encontra o erro TS2339 em open-sse/services/compression/engines/omniglyphAdapter.ts:126. Reproduzi exatamente o mesmo erro no commit base aa912c42, então não foi introduzido por este PR.

O head e os checks estão reconfirmados para a decisão final.

@arafatkatze

Copy link
Copy Markdown
Contributor Author

Oi, @diegosouzapw!
Cobri todos os seus comentários. Você poderia dar uma olhada quando tiver um tempo? Obrigado!

@arafatkatze
arafatkatze force-pushed the arafatkatze/fix-cline-generated-task-id branch 2 times, most recently from d815a6e to fdc6d93 Compare August 21, 2026 01:47
@arafatkatze

Copy link
Copy Markdown
Contributor Author

Oi, @diegosouzapw! Fiz o rebase e corrigi os conflitos. Pode dar uma olhada e fazer o merge, por favor?

@arafatkatze
arafatkatze force-pushed the arafatkatze/fix-cline-generated-task-id branch from fdc6d93 to d01764c Compare August 21, 2026 01:59
@diegosouzapw
diegosouzapw merged commit 967b56a into diegosouzapw:release/v3.8.50 Aug 21, 2026
10 of 16 checks passed
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
Validado no worktree combinado do lote: typecheck:core, lint, gates de qualidade e os 13 testes unitários + 1 de integração (cline-task-id-propagation) todos verdes. Correção legítima de identidade de tarefa fabricada. CI vermelho neste PR é o base-red já rastreado em diegosouzapw#9985. Obrigado!
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants