Skip to content

fix(docs): restore the env/docs contract broken by the #13679 vars - #13875

Merged
diegosouzapw merged 1 commit into
release/v3.8.51from
fix/release-v3.8.51-basereds-env-docs
Sep 16, 2026
Merged

diegosouzapw merged 1 commit into
release/v3.8.51from
fix/release-v3.8.51-basereds-env-docs

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Clears the HARD failure in base-red #13866. check:env-doc-sync fails on the release tip, which
turns "Docs Gates (fast-path)" red on every open PR against release/v3.8.51 — the same seven
checks currently red on #13831 and #13868 come from here.

Both gaps were introduced by #13679:

Var Gap Fix
OMNIROUTE_CLOUD_SYNC_ENFORCE_SIGNATURE read in src/lib/cloudSync.ts, absent from .env.example and ENVIRONMENT.md documented in both
CDP_PROXY_TOKEN in .env.example, absent from ENVIRONMENT.md added to the ChatGPT Web (Codex) table

The descriptions follow the code, not the variable name:

  • the cloud-sync flag only governs the unsigned case when no local secret is configured; a
    signature that IS present is always verified, and always rejected when OMNIROUTE_CLOUD_SYNC_SECRET
    is unset, whatever the flag says. Default off for v3.8.x back-compat; v3.9 flips it.
  • CDP_PROXY_TOKEN is the X-Omni-Cdp-Token the CDP proxy sidecar requires when set; unset, the
    proxy forwards unauthenticated and the compose network chatgpt-web-codex-net is the mitigation.

Docs only — no code change.

Validation

Check Result
check:env-doc-sync ✓ all three directions in sync (817 in .env.example, 834 in ENVIRONMENT.md)
check:docs-sync PASS
check:docs-counts only pre-existing soft drift (cloud-agent counts)

Note: .env.example has no Prettier parser, so it is not covered by the format gate.

`check:env-doc-sync` is failing on the release tip, which fails "Docs Gates
(fast-path)" on every open PR against release/v3.8.51 (base-red #13866).

Both gaps come from #13679:

- `OMNIROUTE_CLOUD_SYNC_ENFORCE_SIGNATURE` is read in src/lib/cloudSync.ts but
  was in neither .env.example nor ENVIRONMENT.md. Documented with the behaviour
  the code actually implements: opt-in rejection of an UNSIGNED response when no
  local secret is configured, default off for v3.8.x back-compat, and a present
  signature always verified — and always rejected when
  OMNIROUTE_CLOUD_SYNC_SECRET is unset — regardless of the flag.
- `CDP_PROXY_TOKEN` was in .env.example but missing from ENVIRONMENT.md. Added to
  the ChatGPT Web (Codex) table next to CHATGPT_WEB_CODEX_CDP_URL, in that
  section's language, describing the X-Omni-Cdp-Token header the sidecar expects
  and the compose-network isolation that applies when it is unset.

Docs only, no code change.

Verified on this branch: check:env-doc-sync reports all three directions in sync
(817 vars in .env.example, 834 in ENVIRONMENT.md); check:docs-sync passes;
check:docs-counts reports only pre-existing soft drift.
@diegosouzapw
diegosouzapw merged commit 5faf44f into release/v3.8.51 Sep 16, 2026
7 of 11 checks passed
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…3679 vars (diegosouzapw#13875)

`check:env-doc-sync` is failing on the release tip, which fails "Docs Gates
(fast-path)" on every open PR against release/v3.8.51 (base-red diegosouzapw#13866).

Both gaps come from diegosouzapw#13679:

- `OMNIROUTE_CLOUD_SYNC_ENFORCE_SIGNATURE` is read in src/lib/cloudSync.ts but
  was in neither .env.example nor ENVIRONMENT.md. Documented with the behaviour
  the code actually implements: opt-in rejection of an UNSIGNED response when no
  local secret is configured, default off for v3.8.x back-compat, and a present
  signature always verified — and always rejected when
  OMNIROUTE_CLOUD_SYNC_SECRET is unset — regardless of the flag.
- `CDP_PROXY_TOKEN` was in .env.example but missing from ENVIRONMENT.md. Added to
  the ChatGPT Web (Codex) table next to CHATGPT_WEB_CODEX_CDP_URL, in that
  section's language, describing the X-Omni-Cdp-Token header the sidecar expects
  and the compose-network isolation that applies when it is unset.

Docs only, no code change.

Verified on this branch: check:env-doc-sync reports all three directions in sync
(817 vars in .env.example, 834 in ENVIRONMENT.md); check:docs-sync passes;
check:docs-counts reports only pre-existing soft drift.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant