Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -154,6 +154,8 @@ sauvegarde dont le contenu diffère, puis réécrit en identifiants sans préfix
| `unsafeAllowNativeLocalExec?` | `boolean` | Ancien booléen de Cursor, équivalent à `nativeLocalExec: "on"` uniquement lorsque le champ plus récent n'est pas défini. |
| `nativeLocalExec?` | `"off" \| "codex-sandbox" \| "on"` | Politique d'exécution locale de Cursor. `off` est la valeur par défaut ; actuellement, `codex-sandbox` échoue de manière sûre comme `off`. |

La création et le remplacement d’un fournisseur (`POST /api/providers`) valident `responsesPath` et `chatCompletionsPath` avant de modifier la configuration en mémoire ou sur disque. Les mêmes règles de chemin s’appliquent au chargement d’un fichier de configuration.

Les fournisseurs à clé API peuvent détenir une clé littérale ou une référence à une variable d'environnement. Les fournisseurs OAuth utilisent le
magasin d'identifiants alimenté par `ocx login` ; le comportement de lancement de Claude Code avec abonnement est
configuré sous [`claudeCode.authMode`](/fr/reference/configuration/server/#claude-code-claudecode).
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -146,6 +146,8 @@ account を削除しても mapping は保持され、同じ id を再追加す
| `unsafeAllowNativeLocalExec?` | `boolean` |カーソルのレガシー ブール値。新しいフィールドが設定されていない場合のみ、`nativeLocalExec: "on"` と同等です。 |
| `nativeLocalExec?` | `"off" \| "codex-sandbox" \| "on"` |カーソルのローカル実行ポリシー。 `off` がデフォルトです。 `codex-sandbox` は現在、`off` と同様にフェールクローズされます。 |

プロバイダーの登録・置換(`POST /api/providers`)では、メモリやファイルの設定を変更する前に `responsesPath` と `chatCompletionsPath` を検証します。 設定ファイルの読み込みにも同じ経路の規則が適用されます。

API キープロバイダーは、リテラルキーまたは環境参照を保持する場合があります。 OAuth プロバイダーは、`ocx login` によって設定された資格情報ストアを使用します。サブスクリプションに基づくクロード コードの起動動作は、[`claudeCode.authMode`](/reference/configuration/server/#claude-code) で構成されます。

## プロバイダーによるアウトバウンドの安全性診断
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -146,6 +146,8 @@ managed map을 활성화하면 privacy-safe selector를 만들고, 이후 계정
| `unsafeAllowNativeLocalExec?` | `boolean` | Cursor 레거시 불리언입니다. 더 새로운 필드가 설정되지 않았을 때만 `nativeLocalExec: "on"`과 같습니다. |
| `nativeLocalExec?` | `"off" \| "codex-sandbox" \| "on"` | Cursor 로컬 실행 정책입니다. 기본값은 `off`입니다. `codex-sandbox`는 현재 `off`처럼 실패를 닫습니다. |

공급자 등록·교체(`POST /api/providers`)는 `responsesPath`와 `chatCompletionsPath`를 검증한 뒤 메모리와 파일의 설정을 변경합니다. 설정 파일을 읽을 때도 같은 경로 규칙을 적용합니다.

API 키 공급자는 리터럴 키나 환경 참조를 둘 수 있습니다. OAuth 공급자는 `ocx login`으로 채워지는 자격 증명 저장소를 사용합니다. 구독 기반 Claude Code 실행 동작은 [`claudeCode.authMode`](/reference/configuration/server/#claude-code)에서 설정합니다.

## 공급자 진단용 외부 요청 안전성
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -224,6 +224,8 @@ Providers can expose a built-in shorthand, such as `agy` for `google-antigravity
| `unsafeAllowNativeLocalExec?` | `boolean` | Cursor legacy boolean, equivalent to `nativeLocalExec: "on"` only when the newer field is unset. |
| `nativeLocalExec?` | `"off" \| "codex-sandbox" \| "on"` | Cursor local-exec policy. `off` is default; `codex-sandbox` currently fails closed like `off`. |

Provider registration and replacement (`POST /api/providers`) validate `responsesPath` and `chatCompletionsPath` before changing live configuration or disk state. The same path rules apply when loading a configuration file.

With `webSearchBridge` enabled, a search continuation stays bound to the API-key selection that
served the first request. Changing the selected key, its reference or resolved value, authentication
mode, or base URL during search or provider pacing ends the turn with a bridge error before another
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -159,6 +159,8 @@ cross-route credential fallback не существует. Строки API GPT-
| `unsafeAllowNativeLocalExec?` | `boolean` | Legacy boolean Cursor, эквивалентен `nativeLocalExec: "on"` только если новое поле не задано. |
| `nativeLocalExec?` | `"off" \| "codex-sandbox" \| "on"` | Политика local-exec для Cursor. `off` — дефолт; `codex-sandbox` сейчас ведёт себя fail-closed как `off`. |

Регистрация и замена провайдера (`POST /api/providers`) проверяют `responsesPath` и `chatCompletionsPath` до изменения конфигурации в памяти или на диске. Те же правила путей применяются при загрузке файла конфигурации.

Провайдеры с API-key могут хранить literal key или environment-reference. OAuth-провайдеры
используют credential store, заполняемый через `ocx login`; поведение subscription-backed launcher'а
Claude Code настраивается через
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -160,6 +160,8 @@ alanlı seçilmiş kimlikleri yalın kimliklere yeniden yazar.
| `unsafeAllowNativeLocalExec?` | `boolean` | Cursor eski boolean değeri, yalnızca daha yeni alan ayarlanmadığında `nativeLocalExec: "on"` değerine eşdeğerdir. |
| `nativeLocalExec?` | `"off" \| "codex-sandbox" \| "on"` | Cursor yerel yürütme politikası. `off` varsayılandır; `codex-sandbox` şu anda `off` gibi kapalı olarak başarısız olur. |

Sağlayıcı kaydı ve değiştirme (`POST /api/providers`), bellekteki veya diskteki yapılandırmayı değiştirmeden önce `responsesPath` ve `chatCompletionsPath` değerlerini doğrular. Aynı yol kuralları yapılandırma dosyası yüklenirken de uygulanır.

API anahtarı sağlayıcıları değişmez bir anahtar veya bir ortam referansı
tutabilir. OAuth sağlayıcıları `ocx login` tarafından doldurulan kimlik bilgisi
deposunu kullanır; abonelik destekli Claude Code başlatma davranışı
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -146,6 +146,8 @@ selector,而不是分配一个新名称。
| `unsafeAllowNativeLocalExec?` | `boolean` | Cursor 旧布尔值;仅当更新字段未设置时,等同于 `nativeLocalExec: "on"`。 |
| `nativeLocalExec?` | `"off" \| "codex-sandbox" \| "on"` | Cursor 本地执行策略。`off` 是默认值;`codex-sandbox` 目前会像 `off` 一样失败关闭。 |

注册或替换提供商(`POST /api/providers`)时,会先验证 `responsesPath` 和 `chatCompletionsPath`,再修改内存或磁盘中的配置。 加载配置文件时也适用同样的路径规则。

API key 提供者可以持有字面量 key,或环境引用。OAuth 提供者使用由 `ocx login` 填充的凭据存储;基于订阅的 Claude Code 启动行为在 [`claudeCode.authMode`](/reference/configuration/server/#claude-code) 下配置。

## 提供者诊断出站安全性
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -116,6 +116,8 @@ ocx models provider openrouter on
| `unsafeAllowNativeLocalExec?` | `boolean` | Cursor 舊版布林值,僅在較新欄位未設定時等同於 `nativeLocalExec: "on"`。 |
| `nativeLocalExec?` | `"off" \| "codex-sandbox" \| "on"` | Cursor 本機執行政策。`off` 為預設;`codex-sandbox` 目前像 `off` 般 fail closed。 |

註冊或替換供應商(`POST /api/providers`)時,會先驗證 `responsesPath` 和 `chatCompletionsPath`,再修改記憶體或磁碟中的設定。 載入設定檔時也適用相同的路徑規則。

API-key 供應商可持有字面值金鑰或環境參考。OAuth 供應商使用由 `ocx login` 填入的憑證存放;訂閱支援的 Claude Code 啟動行為在 [`claudeCode.authMode`](/zh-tw/reference/configuration/server/#claude-code) 下設定。

## 供應商診斷對外安全
Expand Down
6 changes: 5 additions & 1 deletion src/config.ts
Original file line number Diff line number Diff line change
Expand Up @@ -731,8 +731,12 @@ export {
* Shared shape check for the two relative send-path overrides. `field` names the
* offending key so the message stays specific to what the user actually wrote.
*/
function providerRelativeSendPathConfigError(field: string, value: string | undefined): string | null {
export function providerRelativeSendPathConfigError(
field: "responsesPath" | "chatCompletionsPath",
value: unknown,
): string | null {
if (value === undefined) return null;
if (typeof value !== "string") return `${field} must be a string`;
if (/^[A-Za-z][A-Za-z0-9+.-]*:/.test(value) || value.includes("://")) {
return `${field} must be a relative path without a URL scheme`;
}
Expand Down
5 changes: 5 additions & 0 deletions src/server/auth-cors.ts
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@ import {
codexAutoStartEnabled,
modelPreferHostedToolsConfigError,
providerModelCostsConfigError,
providerRelativeSendPathConfigError,
providerWebSearchBridgeConfigError,
requestPacingConfigError,
retryOn429PolicyConfigError,
Expand Down Expand Up @@ -754,6 +755,10 @@ export function providerManagementConfigError(
}
const destinationError = providerDestinationConfigError(name, typed);
if (destinationError) return `provider ${name} ${destinationError}`;
for (const field of ["responsesPath", "chatCompletionsPath"] as const) {
const sendPathError = providerRelativeSendPathConfigError(field, raw[field]);
if (sendPathError) return `provider ${JSON.stringify(redactSecretString(name))} ${sendPathError}`;
}
const headersError = providerHeadersConfigError(typed.headers);
if (headersError) return `provider ${name} ${headersError}`;
const retryOn429Error = retryOn429PolicyConfigError(raw.retryOn429);
Expand Down
2 changes: 2 additions & 0 deletions structure/adapters/registry.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# Adapter Registry Authority

Management provider-validation calls use the [shared relative send-path validation](../config.md#provider-relative-send-paths) before persistence.

The configuration-only [plaintext V2 contract](../subagents.md#plaintext-v2-agent-messages)
is scoped to canonical ChatGPT Responses forwarding; other source-area behavior described here is unchanged.

Expand Down
2 changes: 2 additions & 0 deletions structure/catalog.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# Model Catalog

Management provider-validation calls use the [shared relative send-path validation](config.md#provider-relative-send-paths) before persistence.

The configuration-only [plaintext V2 contract](subagents.md#plaintext-v2-agent-messages)
is scoped to canonical ChatGPT Responses forwarding; other source-area behavior described here is unchanged.

Expand Down
2 changes: 2 additions & 0 deletions structure/clients/claude-desktop.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# Claude Desktop Integration

Management provider-validation calls use the [shared relative send-path validation](../config.md#provider-relative-send-paths) before persistence.

The configuration-only [plaintext V2 contract](../subagents.md#plaintext-v2-agent-messages)
is scoped to canonical ChatGPT Responses forwarding; other source-area behavior described here is unchanged.

Expand Down
11 changes: 11 additions & 0 deletions structure/config.md
Original file line number Diff line number Diff line change
Expand Up @@ -228,6 +228,17 @@ hand-edited `config.json` must accept and reject the same provider shapes.

> Decision record: [ADR-0020](decisions/ADR-0020-provider-validation-ownership.md)

## Provider relative send paths

`src/config.ts` exports `providerRelativeSendPathConfigError` for the schema loader and
`src/server/auth-cors.ts` management validator. Both `responsesPath` and `chatCompletionsPath`
must be strings beginning with `/`, without a scheme, query or fragment; omission is allowed.
Provider registration/replacement rejects invalid values before DNS, persistence or catalog
refresh. Editor PATCH checks also validate retained paths when they revalidate a merged provider;
pacing-only and other existing validation bypasses are unchanged. No send-path PATCH setter is added.
`tests/server/management-provider-validation.test.ts` covers rejection without live/disk mutation
and valid-path persistence/reload through the actual management handler.

## Restore

`ocx stop`, `ocx restore` / `ocx eject`, `ocx service stop`, and `ocx service uninstall` must strip
Expand Down
2 changes: 2 additions & 0 deletions structure/data-planes/images.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# Images Data Plane

Management provider-validation calls use the [shared relative send-path validation](../config.md#provider-relative-send-paths) before persistence.

The configuration-only [plaintext V2 contract](../subagents.md#plaintext-v2-agent-messages)
is scoped to canonical ChatGPT Responses forwarding; other source-area behavior described here is unchanged.

Expand Down
2 changes: 2 additions & 0 deletions structure/data-planes/inbound-compat.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# Inbound Compatibility Surfaces

Management provider-validation calls use the [shared relative send-path validation](../config.md#provider-relative-send-paths) before persistence.

The configuration-only [plaintext V2 contract](../subagents.md#plaintext-v2-agent-messages)
is scoped to canonical ChatGPT Responses forwarding; other source-area behavior described here is unchanged.

Expand Down
2 changes: 1 addition & 1 deletion structure/gui-and-management-api.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# GUI And Management API

The configuration-only [plaintext V2 contract](subagents.md#plaintext-v2-agent-messages)
is scoped to canonical ChatGPT Responses forwarding; other source-area behavior described here is unchanged.
is scoped to canonical ChatGPT Responses forwarding; other source-area behavior described here is unchanged. Management provider-validation calls use the [shared relative send-path validation](config.md#provider-relative-send-paths) before persistence.

## Dashboard serving

Expand Down
2 changes: 2 additions & 0 deletions structure/ops/service-and-sidecars.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# Background Service And Sidecars

Management provider-validation calls use the [shared relative send-path validation](../config.md#provider-relative-send-paths) before persistence.

The configuration-only [plaintext V2 contract](../subagents.md#plaintext-v2-agent-messages)
is scoped to canonical ChatGPT Responses forwarding; other source-area behavior described here is unchanged.

Expand Down
2 changes: 2 additions & 0 deletions structure/overview.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# Overview

Management provider-validation calls use the [shared relative send-path validation](config.md#provider-relative-send-paths) before persistence.

The configuration-only [plaintext V2 contract](subagents.md#plaintext-v2-agent-messages)
is scoped to canonical ChatGPT Responses forwarding; other source-area behavior described here is unchanged.

Expand Down
2 changes: 2 additions & 0 deletions structure/providers/openai-tiers.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# OpenAI Provider Account Modes

Management provider-validation calls use the [shared relative send-path validation](../config.md#provider-relative-send-paths) before persistence.

The configuration-only [plaintext V2 contract](../subagents.md#plaintext-v2-agent-messages)
is scoped to canonical ChatGPT Responses forwarding; other source-area behavior described here is unchanged.

Expand Down
2 changes: 2 additions & 0 deletions structure/providers/xai-grok.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# xAI Grok Provider

Management provider-validation calls use the [shared relative send-path validation](../config.md#provider-relative-send-paths) before persistence.

The configuration-only [plaintext V2 contract](../subagents.md#plaintext-v2-agent-messages)
is scoped to canonical ChatGPT Responses forwarding; other source-area behavior described here is unchanged.

Expand Down
2 changes: 2 additions & 0 deletions structure/runtime.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# Runtime

Management provider-validation calls use the [shared relative send-path validation](config.md#provider-relative-send-paths) before persistence.

The configuration-only [plaintext V2 contract](subagents.md#plaintext-v2-agent-messages)
is scoped to canonical ChatGPT Responses forwarding; other source-area behavior described here is unchanged.

Expand Down
2 changes: 2 additions & 0 deletions structure/subagents.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# Subagents And Multi-Agent Surface

Management provider-validation calls use the [shared relative send-path validation](config.md#provider-relative-send-paths) before persistence.

## Plaintext V2 agent messages

`src/responses/plaintext-v2-agent-messages.ts` owns the experimental, configuration-only
Expand Down
2 changes: 2 additions & 0 deletions structure/transports/byte-accounting.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# Byte Accounting

Management provider-validation calls use the [shared relative send-path validation](../config.md#provider-relative-send-paths) before persistence.

How opencodex measures request and stream bytes without allocating copies solely to count
them. These contracts are shared by request parsing, SSE rewriting, the provider adapters and
the translator budget, which is why so many documents link here rather than restating them.
Expand Down
2 changes: 2 additions & 0 deletions structure/transports/inventory.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# Transport Inventory

Management provider-validation calls use the [shared relative send-path validation](../config.md#provider-relative-send-paths) before persistence.

The configuration-only [plaintext V2 contract](../subagents.md#plaintext-v2-agent-messages)
is scoped to canonical ChatGPT Responses forwarding; other source-area behavior described here is unchanged.

Expand Down
2 changes: 1 addition & 1 deletion structure/transports/responses.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# Responses Transport

The configuration-only [plaintext V2 contract](../subagents.md#plaintext-v2-agent-messages)
is scoped to canonical ChatGPT Responses forwarding; other source-area behavior described here is unchanged.
is scoped to canonical ChatGPT Responses forwarding; other source-area behavior described here is unchanged. Management provider-validation calls use the [shared relative send-path validation](../config.md#provider-relative-send-paths) before persistence.

Plaintext collaboration restoration treats a null namespace as absent, rejects non-string namespace types, and restores the native namespace/name pair before HTTP/WS delivery and continuation publication.

Expand Down
2 changes: 2 additions & 0 deletions structure/transports/streaming-health.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# Streaming Health And WebSocket

Management provider-validation calls use the [shared relative send-path validation](../config.md#provider-relative-send-paths) before persistence.

The configuration-only [plaintext V2 contract](../subagents.md#plaintext-v2-agent-messages)
is scoped to canonical ChatGPT Responses forwarding; other source-area behavior described here is unchanged.

Expand Down
Loading
Loading