Skip to content

fix(server): allow POST /v1/alpha/search on the loopback listener - #3205

Merged
lidge-jun merged 1 commit into
devfrom
codex/260902-p3193-loopback-alpha-search
Sep 1, 2026
Merged

lidge-jun merged 1 commit into
devfrom
codex/260902-p3193-loopback-alpha-search

Conversation

@lidge-jun

@lidge-jun lidge-jun commented Sep 1, 2026 •

Copy link
Copy Markdown
Owner

Summary

Native Codex web search through the unauthenticated loopback listener returned 404 Unknown endpoint because loopbackRouteAllowed() in src/server/index.ts never admitted /v1/alpha/search. This admits POST on that path. The handler keeps its own admission (resolveApiAuth + validateForwardAdmissionCredential in handleSearch), so a loopback caller without a ChatGPT credential is still refused inside the relay; only the listener-level 404 goes away. The public listener is unchanged and still answers 401 opencodex API key required.

Clean reimplementation of #3193 by @alan7629, whose branch was byte-corrupted by an encoding round-trip (em-dashes and emoji rewritten in ~30 unrelated comment lines). Credited via Co-authored-by.

Also updates the docs-site loopback allowlist paragraph (en, fr, zh-tw, tr — the locales that document it) to list POST /v1/alpha/search and the realtime voice upgrades.

Supersedes #3193. Fixes #3192.

Verification

  • bun test tests/loopback-listener-integration.test.ts → 29 pass / 0 fail. New case: POST /v1/alpha/search on the loopback listener is not 404 and its body comes from behind the gate (non-API-key message; 503 native-main maintenance or the relay's 401), while the public listener still returns 401 opencodex API key required; GET on the path still 404s via the method-mismatch list.
  • bun run typecheck clean; bun run privacy:scan passed.
  • Full suite deferred to CI (maintainer bypass, tracked after merge).

Checklist

  • Targets dev
  • Focused regression test added next to the existing loopback listener tests
  • Docs-site updated (en + locales that document the allowlist)
  • No GUI change (no screenshot needed)
  • Security: no new unauthenticated capability beyond what /v1/responses already grants on this listener; handler-level admission retained

Summary by CodeRabbit

  • New Features

    • Native web-search relay requests are now supported through the unauthenticated loopback listener.
    • Standalone voice WebSocket connections are documented as supported on the loopback listener.
  • Documentation

    • Updated server configuration references in English, French, Turkish, and Traditional Chinese.
    • Clarified that unsupported routes, including /api/* and the dashboard, continue to return 404.

The unauthenticated loopback listener admits routes through an allowlist
in loopbackRouteAllowed(). /v1/alpha/search - the native Codex web-search
relay - was never on it, so a directly-spawned codex app-server got 404
for every web search (#3192).

Admit POST on that path. The handler runs its own admission
(resolveApiAuth + validateForwardAdmissionCredential), so a loopback
caller without a ChatGPT credential is still refused inside the relay;
only the listener's 404 goes away. The public listener is unchanged.

Clean reimplementation of #3193, whose branch was byte-corrupted by an
encoding round-trip (em-dashes and emoji in ~30 unrelated comment lines).

Supersedes #3193. Fixes #3192.

Co-authored-by: alan7629 <alan7629@gmail.com>
@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner September 1, 2026 19:13
@lidge-jun lidge-jun added the bug Something isn't working label Sep 1, 2026
@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@lidge-jun
lidge-jun merged commit 53c09a2 into dev Sep 1, 2026
9 of 11 checks passed
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-01T19:16:10.340922Z 1b21bd6 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@lidge-jun
lidge-jun deleted the codex/260902-p3193-loopback-alpha-search branch September 1, 2026 19:13
@coderabbitai

coderabbitai Bot commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Team

Run ID: c920905f-6f38-4ea6-ae18-55b6483ff8a6

📥 Commits

Reviewing files that changed from the base of the PR and between fcf0da2 and 1b21bd6.

📒 Files selected for processing (6)
  • docs-site/src/content/docs/fr/reference/configuration/server.md
  • docs-site/src/content/docs/reference/configuration/server.md
  • docs-site/src/content/docs/tr/reference/configuration/server.md
  • docs-site/src/content/docs/zh-tw/reference/configuration/server.md
  • src/server/index.ts
  • tests/loopback-listener-integration.test.ts

📝 Walkthrough

Walkthrough

The unauthenticated loopback listener now allows POST /v1/alpha/search. Integration tests verify loopback admission and public-listener authentication. English, French, Turkish, and Traditional Chinese server documentation lists the updated endpoint behavior.

Changes

Loopback search route

Layer / File(s) Summary
Allowlist and endpoint documentation
src/server/index.ts, docs-site/src/content/docs/*/reference/configuration/server.md
At src/server/index.ts:783-789, the allowlist documentation describes the web-search route and handler admission checks. At src/server/index.ts:803, POST /v1/alpha/search is admitted on the unauthenticated loopback listener. The localized references document this route and standalone voice WebSocket upgrades.
Route admission tests
tests/loopback-listener-integration.test.ts
At lines 271 and 288-294, the tests remove POST /v1/alpha/search from denied routes and reject unsupported GET requests. Lines 312-346 verify loopback admission returns 401 or 503 instead of 404, while the public listener returns the API-key error.

Estimated code review effort: 2 (Simple) | ~10 minutes

Suggested reviewers: ingwannu, luvs01

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/260902-p3193-loopback-alpha-search

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

lidge-jun pushed a commit that referenced this pull request Sep 1, 2026
lidge-jun pushed a commit that referenced this pull request Sep 1, 2026
lidge-jun pushed a commit that referenced this pull request Sep 2, 2026
lidge-jun pushed a commit that referenced this pull request Sep 2, 2026
lidge-jun added a commit that referenced this pull request Sep 2, 2026
…sion audit (#3218)

* docs(devlog): open the bug/PR closeout stack roadmap

* docs(devlog): fold the A-gate import-boundary finding into phase 5

* docs(devlog): record the #3163 and #3166 landings

* docs(devlog): record why #2986 does not land in this train

* docs(devlog): close out the bug/PR closeout stack

* docs(devlog): record the final green CI verdict on dev

* docs(devlog): open the bug-label drawdown roadmap with audit corrections

* docs(devlog): record the Batch A landings and first rebase carry

* docs(devlog): record the Batch B rebase carries

* docs(devlog): record why the rebase service earned its keep

* docs(devlog): record the Batch C rebases and the one real review finding

* docs(devlog): record the #2999 scope boundary that survived execution

* docs(devlog): record Batch D - every bug PR closed

* docs(devlog): record what the PR half of the campaign cost

* docs(devlog): replan the remaining issues to one per cycle

* docs(devlog): carry the i3141 evidence into the replan

* docs(devlog): diagnose i3141 - fix predates the reported version

* docs(devlog): retire the second bundle

* docs(devlog): record the i3141 re-triage action and outcome

* docs(devlog): diagnose i3152 log table jitter

* docs(devlog): i3152 - measurement disproved the layout diagnosis

* docs(devlog): diagnose i3136 slashed-id price lookup

* docs(devlog): diagnose i3150 citation marker passthrough

* docs(devlog): diagnose i3155 capacity plan allowlist

* docs(devlog): i1419 stays open pending crash frames

* docs(devlog): record the i1419 re-triage ask

* docs(devlog): diagnose i2999 publication overwrite race

* docs(devlog): record the i2999 outcome and remaining scope

* docs(devlog): diagnose i2813 as a client-side reserve gate

* docs(devlog): diagnose i1527 residuals as trace-blocked

* docs(devlog): correct i1527 envelope-cap wording (192 blobs, HTTP 400)

* docs(devlog): plan p3193 loopback alpha-search reimplementation

* docs(devlog): record p3193 landing (#3205 -> 53c09a2)

* docs(devlog): plan the main->dev regression audit

* docs(devlog): pin regaudit counts, add tests-only/security passes and the exact-head dispatch

* docs(devlog): record regaudit reviewer verdicts

* docs(devlog): record the exact-head dev CI verdict and Windows classification

* docs(devlog): record the main control run proving the Windows failures predate the range

* docs(devlog): record the pass-1 recount and the #3217 root cause

* docs(devlog): plan i3217 (Spark functions-namespace flattening)

* docs(devlog): record i3217 landing (#3224 -> d23eab4)

* docs(devlog): regaudit2 recount and disposition table

* docs(devlog): regaudit2 CI verdict on d23eab4 and the four PR arrivals

* docs(devlog): plan p3226 (scoped namespace scrub)

* docs(devlog): p3226 audit finding and carry plan

* docs(devlog): record p3226 landing (#3234 -> b732b0d)

* docs(devlog): plan p3227 (combo zero-output incomplete failover)

* docs(devlog): record p3227 landing

* docs(devlog): plan p3228 (encrypted V2 spawn native fallback)

* docs(devlog): record p3228 landing

* docs(devlog): plan p3229 (Codexless originator in task recovery)

* docs(devlog): record p3229 landing and the #3239 regression repair

* docs(devlog): r3239 regression repair record

* docs(devlog): r3239 audit note

* docs(devlog): record p3232 (merged by maintainer)

* docs(devlog): p3232 verification result

* docs(devlog): regaudit3 recount and landing table

* docs(devlog): record the #3239/#3240 revert and correct the #3228 disposition

* docs(devlog): rv3239 revert record

* docs(devlog): rv3239 audit note

* docs(devlog): regaudit3 second-dispatch verdict

* docs(devlog): regaudit3 recount refreshed (#1419 closed by maintainer; count 4)

* docs(devlog): regaudit3 final CI verdict and c-7

---------

Co-authored-by: jun <jun@lidge.dev>
tarunravi pushed a commit to tarunravi/opencodex that referenced this pull request Sep 14, 2026
…dge-jun#3205)

The unauthenticated loopback listener admits routes through an allowlist
in loopbackRouteAllowed(). /v1/alpha/search - the native Codex web-search
relay - was never on it, so a directly-spawned codex app-server got 404
for every web search (lidge-jun#3192).

Admit POST on that path. The handler runs its own admission
(resolveApiAuth + validateForwardAdmissionCredential), so a loopback
caller without a ChatGPT credential is still refused inside the relay;
only the listener's 404 goes away. The public listener is unchanged.

Clean reimplementation of lidge-jun#3193, whose branch was byte-corrupted by an
encoding round-trip (em-dashes and emoji in ~30 unrelated comment lines).

Supersedes lidge-jun#3193. Fixes lidge-jun#3192.

Co-authored-by: jun <jun@lidge.dev>
Co-authored-by: alan7629 <alan7629@gmail.com>
tarunravi pushed a commit to tarunravi/opencodex that referenced this pull request Sep 14, 2026
…sion audit (lidge-jun#3218)

* docs(devlog): open the bug/PR closeout stack roadmap

* docs(devlog): fold the A-gate import-boundary finding into phase 5

* docs(devlog): record the lidge-jun#3163 and lidge-jun#3166 landings

* docs(devlog): record why lidge-jun#2986 does not land in this train

* docs(devlog): close out the bug/PR closeout stack

* docs(devlog): record the final green CI verdict on dev

* docs(devlog): open the bug-label drawdown roadmap with audit corrections

* docs(devlog): record the Batch A landings and first rebase carry

* docs(devlog): record the Batch B rebase carries

* docs(devlog): record why the rebase service earned its keep

* docs(devlog): record the Batch C rebases and the one real review finding

* docs(devlog): record the lidge-jun#2999 scope boundary that survived execution

* docs(devlog): record Batch D - every bug PR closed

* docs(devlog): record what the PR half of the campaign cost

* docs(devlog): replan the remaining issues to one per cycle

* docs(devlog): carry the i3141 evidence into the replan

* docs(devlog): diagnose i3141 - fix predates the reported version

* docs(devlog): retire the second bundle

* docs(devlog): record the i3141 re-triage action and outcome

* docs(devlog): diagnose i3152 log table jitter

* docs(devlog): i3152 - measurement disproved the layout diagnosis

* docs(devlog): diagnose i3136 slashed-id price lookup

* docs(devlog): diagnose i3150 citation marker passthrough

* docs(devlog): diagnose i3155 capacity plan allowlist

* docs(devlog): i1419 stays open pending crash frames

* docs(devlog): record the i1419 re-triage ask

* docs(devlog): diagnose i2999 publication overwrite race

* docs(devlog): record the i2999 outcome and remaining scope

* docs(devlog): diagnose i2813 as a client-side reserve gate

* docs(devlog): diagnose i1527 residuals as trace-blocked

* docs(devlog): correct i1527 envelope-cap wording (192 blobs, HTTP 400)

* docs(devlog): plan p3193 loopback alpha-search reimplementation

* docs(devlog): record p3193 landing (lidge-jun#3205 -> 53c09a2)

* docs(devlog): plan the main->dev regression audit

* docs(devlog): pin regaudit counts, add tests-only/security passes and the exact-head dispatch

* docs(devlog): record regaudit reviewer verdicts

* docs(devlog): record the exact-head dev CI verdict and Windows classification

* docs(devlog): record the main control run proving the Windows failures predate the range

* docs(devlog): record the pass-1 recount and the lidge-jun#3217 root cause

* docs(devlog): plan i3217 (Spark functions-namespace flattening)

* docs(devlog): record i3217 landing (lidge-jun#3224 -> d23eab4)

* docs(devlog): regaudit2 recount and disposition table

* docs(devlog): regaudit2 CI verdict on d23eab4 and the four PR arrivals

* docs(devlog): plan p3226 (scoped namespace scrub)

* docs(devlog): p3226 audit finding and carry plan

* docs(devlog): record p3226 landing (lidge-jun#3234 -> b732b0d)

* docs(devlog): plan p3227 (combo zero-output incomplete failover)

* docs(devlog): record p3227 landing

* docs(devlog): plan p3228 (encrypted V2 spawn native fallback)

* docs(devlog): record p3228 landing

* docs(devlog): plan p3229 (Codexless originator in task recovery)

* docs(devlog): record p3229 landing and the lidge-jun#3239 regression repair

* docs(devlog): r3239 regression repair record

* docs(devlog): r3239 audit note

* docs(devlog): record p3232 (merged by maintainer)

* docs(devlog): p3232 verification result

* docs(devlog): regaudit3 recount and landing table

* docs(devlog): record the lidge-jun#3239/lidge-jun#3240 revert and correct the lidge-jun#3228 disposition

* docs(devlog): rv3239 revert record

* docs(devlog): rv3239 audit note

* docs(devlog): regaudit3 second-dispatch verdict

* docs(devlog): regaudit3 recount refreshed (lidge-jun#1419 closed by maintainer; count 4)

* docs(devlog): regaudit3 final CI verdict and c-7

---------

Co-authored-by: jun <jun@lidge.dev>
agentHits pushed a commit to agentHits/opencodex that referenced this pull request Sep 17, 2026
…dge-jun#3205)

The unauthenticated loopback listener admits routes through an allowlist
in loopbackRouteAllowed(). /v1/alpha/search - the native Codex web-search
relay - was never on it, so a directly-spawned codex app-server got 404
for every web search (lidge-jun#3192).

Admit POST on that path. The handler runs its own admission
(resolveApiAuth + validateForwardAdmissionCredential), so a loopback
caller without a ChatGPT credential is still refused inside the relay;
only the listener's 404 goes away. The public listener is unchanged.

Clean reimplementation of lidge-jun#3193, whose branch was byte-corrupted by an
encoding round-trip (em-dashes and emoji in ~30 unrelated comment lines).

Supersedes lidge-jun#3193. Fixes lidge-jun#3192.

Co-authored-by: jun <jun@lidge.dev>
Co-authored-by: alan7629 <alan7629@gmail.com>
agentHits pushed a commit to agentHits/opencodex that referenced this pull request Sep 17, 2026
…sion audit (lidge-jun#3218)

* docs(devlog): open the bug/PR closeout stack roadmap

* docs(devlog): fold the A-gate import-boundary finding into phase 5

* docs(devlog): record the lidge-jun#3163 and lidge-jun#3166 landings

* docs(devlog): record why lidge-jun#2986 does not land in this train

* docs(devlog): close out the bug/PR closeout stack

* docs(devlog): record the final green CI verdict on dev

* docs(devlog): open the bug-label drawdown roadmap with audit corrections

* docs(devlog): record the Batch A landings and first rebase carry

* docs(devlog): record the Batch B rebase carries

* docs(devlog): record why the rebase service earned its keep

* docs(devlog): record the Batch C rebases and the one real review finding

* docs(devlog): record the lidge-jun#2999 scope boundary that survived execution

* docs(devlog): record Batch D - every bug PR closed

* docs(devlog): record what the PR half of the campaign cost

* docs(devlog): replan the remaining issues to one per cycle

* docs(devlog): carry the i3141 evidence into the replan

* docs(devlog): diagnose i3141 - fix predates the reported version

* docs(devlog): retire the second bundle

* docs(devlog): record the i3141 re-triage action and outcome

* docs(devlog): diagnose i3152 log table jitter

* docs(devlog): i3152 - measurement disproved the layout diagnosis

* docs(devlog): diagnose i3136 slashed-id price lookup

* docs(devlog): diagnose i3150 citation marker passthrough

* docs(devlog): diagnose i3155 capacity plan allowlist

* docs(devlog): i1419 stays open pending crash frames

* docs(devlog): record the i1419 re-triage ask

* docs(devlog): diagnose i2999 publication overwrite race

* docs(devlog): record the i2999 outcome and remaining scope

* docs(devlog): diagnose i2813 as a client-side reserve gate

* docs(devlog): diagnose i1527 residuals as trace-blocked

* docs(devlog): correct i1527 envelope-cap wording (192 blobs, HTTP 400)

* docs(devlog): plan p3193 loopback alpha-search reimplementation

* docs(devlog): record p3193 landing (lidge-jun#3205 -> 144ddf4)

* docs(devlog): plan the main->dev regression audit

* docs(devlog): pin regaudit counts, add tests-only/security passes and the exact-head dispatch

* docs(devlog): record regaudit reviewer verdicts

* docs(devlog): record the exact-head dev CI verdict and Windows classification

* docs(devlog): record the main control run proving the Windows failures predate the range

* docs(devlog): record the pass-1 recount and the lidge-jun#3217 root cause

* docs(devlog): plan i3217 (Spark functions-namespace flattening)

* docs(devlog): record i3217 landing (lidge-jun#3224 -> fe855b3)

* docs(devlog): regaudit2 recount and disposition table

* docs(devlog): regaudit2 CI verdict on fe855b3 and the four PR arrivals

* docs(devlog): plan p3226 (scoped namespace scrub)

* docs(devlog): p3226 audit finding and carry plan

* docs(devlog): record p3226 landing (lidge-jun#3234 -> 827456e)

* docs(devlog): plan p3227 (combo zero-output incomplete failover)

* docs(devlog): record p3227 landing

* docs(devlog): plan p3228 (encrypted V2 spawn native fallback)

* docs(devlog): record p3228 landing

* docs(devlog): plan p3229 (Codexless originator in task recovery)

* docs(devlog): record p3229 landing and the lidge-jun#3239 regression repair

* docs(devlog): r3239 regression repair record

* docs(devlog): r3239 audit note

* docs(devlog): record p3232 (merged by maintainer)

* docs(devlog): p3232 verification result

* docs(devlog): regaudit3 recount and landing table

* docs(devlog): record the lidge-jun#3239/lidge-jun#3240 revert and correct the lidge-jun#3228 disposition

* docs(devlog): rv3239 revert record

* docs(devlog): rv3239 audit note

* docs(devlog): regaudit3 second-dispatch verdict

* docs(devlog): regaudit3 recount refreshed (lidge-jun#1419 closed by maintainer; count 4)

* docs(devlog): regaudit3 final CI verdict and c-7

---------

Co-authored-by: jun <jun@lidge.dev>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant