Skip to content

📔 feat: Preserve Owner Text During PII Redaction - #16311

Merged
danny-avila merged 22 commits into
devfrom
lia/pii-owner-view
Oct 2, 2026
Merged

danny-avila merged 22 commits into
devfrom
lia/pii-owner-view

Conversation

@lia-by-librechat

@lia-by-librechat lia-by-librechat Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Opt-in filters.messages.pii.action: redact filters fresh text-only interactive Agent turns. Owners can reload encrypted originals through a separate authenticated display endpoint. Default behavior and unsupported ingress remain blocking.

Canonical filtered text feeds models, storage, ordinary reads, search, sharing and exports. Originals/ciphertext stay outside those paths and diagnostics.

Mechanism

supported text → bounded transform → canonical placeholders + encrypted capture
content admission → atomic protected write → created / primary model / title / memory
rejected admission → no revival through terminal recovery
owner batch read → owner + tenant + expiry + AES-GCM binding → display only
native copies → canonical text + server-only token provenance, never owner originals
  • Unindexed select: false sidecars share message deletion/TTL. Domain-separated AES-GCM derived from CREDS_KEY binds owner, tenant, conversation, message, revision and canonical text.
  • Only canonical server-owned rows establish exact generated-token trust. Surrounding text, forged tokens and independent source policies remain inspected.
  • Protected persistence stays deferred until every starting root passes exact native-input admission; no root can invoke its model before the shared protected write. Missing writers, failed writes and policy rejection fail closed. Admission is irrevocable: rejected turns cannot be revived by error recovery or a late write. Already-admitted turns and ordinary error history retain their normal behavior.
  • Protected writes complete before owner-readable created and primary-model invocation. Title and automatic memory extraction await that same admission and observe cancellation. Pre-admission Stop cancels the pending protected writer. Already-admitted and ordinary Stop retain their durability behavior. Stop verifies stored protection; revisionless prerequisites are insert-only, including literal placeholder text.
  • Owner reads use dedicated keys in an isolated shared React Query client, outside ordinary caches/devtools/persistence. Inactive lifetime is zero. Requests hold at most 50 IDs with three concurrent batches. Reuse binds owner, tenant, conversation, revision and canonical text. Manual retry and one provisional completion retry remain available.
  • Native fork/duplicate/shared copies preserve hidden, unindexed canonical-token provenance, not ciphertext or owner-readable revisions. Untrusted imports and canonical overwrites clear it. Ordinary/public/export DTOs exclude it. Copies support follow-up model calls, sharing and further copies.
  • Search uses a public projection. Text exports fetch the canonical server transcript and fail closed. Screenshots reject protected or unacknowledged text and pin conversation/DOM identity across mounting, cloning, encoding and download.
  • Dev's versioned/App-budget writer, retention and reply stamping remain intact.

Scope and rollout

Fresh text-only interactive Agent submissions only. Not included: default-on protection, alternate ingress, files/quotes, edits/regenerations/resumes, bound-secret/background-tool redaction or historical migration. Unsaved denied first turns do not advertise recoverable originals. A fresh protected turn requiring automatic summarization before initial native admission fails closed in this slice; it neither invokes that model early nor deadlocks parallel roots.

A retained valid CREDS_KEY is required. No previous-key ring: key loss/rotation makes older originals unavailable; canonical history remains usable. Preserve encrypted key backups. Rollback to block stops new transformations without restoring originals into canonical storage. Older builds may block native copies whose provenance they cannot recognize; they do not gain access to originals. Historical PII and infrastructure request-body capture are not removed.

Verification

  • Current head: 289 policy/private/admission/memory tests and 651 Agent/BaseClient/recovery/Stop tests passed. The admission tests use real LangChain callback dispatch and real Agent SDK parallel graphs with fake provider transport.
  • API tsc --noEmit, real API build and PR-wide static checks passed.
  • All five current-head browser scenarios passed: owner streaming/reload; canonical model/storage/share/export boundaries; protected screenshot refusal and safe PNG export; native/repeated/shared copies; rejected-history no-save behavior.
  • Current-head Lighthouse CI passed. Local Lighthouse attempts timed out; the latest local attempt could not start because workspace capacity was unavailable. No local performance result is claimed.
  • Independent frozen-head review completed with no new findings. It read the full diff, traced the lifecycle boundaries, revalidated the finding ledger and passed six dependency-free checks. It did not independently run repository suites, SDK/Mongo/browser integrations, types, builds or Lighthouse.
  • Preceding latest-dev merged head also passed 1,550 focused tests, five workspace typechecks, four package builds and the production frontend build. These are not claimed as independent current-head test coverage.
  • Full config-migration tests, unused i18n-key/package scans and full-monorepo local suites were not run. Typechecks were separate from builds/static checks.
  • CI: 4 in_progress, 2 skipped, 38 success.

Integrated dev@abab0d3c6d48dac3c58538ffa404676b9e477440 without rewriting history. Pushed and independently reviewed head: 7b9013e45a949e3aa1d44485c79d024d0539baed. Original Codex threads are answered and resolved. All supported independent findings are fixed; current-head review found none. No findings rejected.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review handoff for exact remote head 7117f1d40c016fbe5bdc370221806d95ce28ec52.

PR 2 adds opt-in text-only interactive redaction, atomic canonical text plus encrypted owner sidecar storage, a tenant/owner-authorized batch view, and a display-only UI context. Normal history, sharing, exports, request execution, and diagnostics do not receive the original. The browser test inspects the actual mock-provider message projection, then exercises owner reload, network retry, sharing, unauthorized retrieval, ciphertext storage, and deletion.

Verification: 681 focused tests passed (139 API, 142 data-schemas, 14 filter-schema, 74 client, 312 legacy/controller); the final browser test passed; all four changed TypeScript workspace checks, package builds, and staged static checks passed. The synthetic PII canary was absent from the successful browser-run server log.

Invariant self-review covered ingress ordering, initial and fallback writers, persistence failure/admission, retry identity, tenant and owner isolation, canonical/share readers, display-cache invalidation, expiry/deletion, and rollback. No independent review has arrived for this head yet.

Explicit limits: the default is unchanged; non-text and alternate ingress retain blocking; no historical migration or bound-secret protection is enabled here. The sidecar shares message deletion/retention. CREDS_KEY rotation without retaining the old key makes prior originals unreadable; canonical filtered content remains usable.

Local Lighthouse was attempted before and after UI changes but did not produce a passing result: the initial full-browser launch lacked system libraries and the later audit exceeded the 90-second tool budget. No performance score is claimed. Light/dark screenshots were captured, but GitHub media upload rejected App authentication and they are not attached. CI and fresh review still need to cover this SHA.

@github-actions

Copy link
Copy Markdown
Contributor

Lighthouse CI failed. The last 80 log lines contain the measured budgets and assertion failures.

│ 21      │ 'http://localhost:3080/api/convos?pinned=true&limit=100'                                                        │ 2719.539999999979  │ 3477.017999999982  │ 200    │
│ 22      │ 'http://localhost:3080/api/mcp/servers'                                                                         │ 3049.9229999999807 │ 4313.694999999978  │ 200    │
│ 23      │ 'http://localhost:3080/api/permissions/mcpServer/effective/all'                                                 │ 3051.25999999998   │ 3810.5049999999756 │ 200    │
│ 24      │ 'http://localhost:3080/api/prompts/groups?limit=10'                                                             │ 3051.5409999999683 │ 4325.273999999976  │ 200    │
│ 25      │ 'http://localhost:3080/api/keys?name=openAI'                                                                    │ 3275.359999999957  │ 3986.109999999986  │ 200    │
│ 26      │ 'http://localhost:3080/api/presets'                                                                             │ 3277.0229999999865 │ 3986.356999999989  │ 200    │
│ 27      │ 'http://localhost:3080/api/tags'                                                                                │ 3277.2849999999744 │ 3991.1199999999953 │ 200    │
│ 28      │ 'http://localhost:3080/api/share/link/16390000-0000-4000-8000-000000000001'                                     │ 3277.508999999962  │ 4315.609999999986  │ 200    │
│ 29      │ 'http://localhost:3080/api/messages/16390000-0000-4000-8000-000000000001'                                       │ 3277.6789999999746 │ 4495.280999999959  │ 200    │
│ 30      │ 'http://localhost:3080/api/files/config'                                                                        │ 3278.92399999997   │ 4244.030999999959  │ 200    │
│ 31      │ 'http://localhost:3080/api/agents/tools/web_search/auth'                                                        │ 3279.1419999999634 │ 7012.731           │ 200    │
│ 32      │ 'http://localhost:3080/api/endpoints/token-config'                                                              │ 3280.0049999999756 │ 4501.006999999983  │ 200    │
│ 33      │ 'http://localhost:3080/api/agents/tools/calls?conversationId=16390000-0000-4000-8000-000000000001'              │ 3280.2369999999937 │ 4821.611999999965  │ 200    │
│ 34      │ 'http://localhost:3080/api/agents/chat/status/16390000-0000-4000-8000-000000000001?generationProtocolVersion=2' │ 4588.020999999979  │ 4843.293999999965  │ 200    │
└─────────┴─────────────────────────────────────────────────────────────────────────────────────────────────────────────────┴────────────────────┴────────────────────┴────────┘

Inspect .lighthouse HTML/JSON and e2e/lighthouse/README.md. Reuse loaded user/config data; overlap independent reads without bypassing authorization.

┌─────────┬────────────────────────────┬──────────────────────┬───────┐
│ (index) │ audit                      │ median               │ limit │
├─────────┼────────────────────────────┼──────────────────────┼───────┤
│ 0       │ 'largest-contentful-paint' │ 4537.837             │ 4500  │
│ 1       │ 'cumulative-layout-shift'  │ 0.016891882223535586 │ 0.1   │
│ 2       │ 'total-blocking-time'      │ 203.86200000000008   │ 500   │
└─────────┴────────────────────────────┴──────────────────────┴───────┘

  1) [chrome] › e2e/lighthouse/load.spec.ts:10:5 › serial database latency stays within web-vitals budgets 

    Error: Median largest-contentful-paint must stay within 4500

    expect(received).toBeLessThanOrEqual(expected)

    Expected: <= 4500
    Received:    4537.837

       at audit.ts:159

      157 |   console.table(measured);
      158 |   for (const { audit, median, limit } of measured) {
    > 159 |     expect(median, `Median ${audit} must stay within ${limit}`).toBeLessThanOrEqual(limit);
          |                                                                 ^
      160 |   }
      161 |   return results;
      162 | }
        at auditPage (/home/runner/work/LibreChat/LibreChat/e2e/lighthouse/audit.ts:159:65)
        at /home/runner/work/LibreChat/LibreChat/e2e/lighthouse/load.spec.ts:33:19

    attachment #1: screenshot (image/png) ──────────────────────────────────────────────────────────
    e2e/lighthouse/.test-results/load-serial-database-latency-stays-within-web-vitals-budgets-chrome/test-failed-1.png
    ────────────────────────────────────────────────────────────────────────────────────────────────

    Error Context: e2e/lighthouse/.test-results/load-serial-database-latency-stays-within-web-vitals-budgets-chrome/error-context.md

    attachment #3: trace (application/zip) ─────────────────────────────────────────────────────────
    e2e/lighthouse/.test-results/load-serial-database-latency-stays-within-web-vitals-budgets-chrome/trace.zip
    Usage:

        npx playwright show-trace e2e/lighthouse/.test-results/load-serial-database-latency-stays-within-web-vitals-budgets-chrome/trace.zip

    ────────────────────────────────────────────────────────────────────────────────────────────────


🤖: global teardown has been started
2026-09-24 13:33:03 �[32minfo�[39m: �[32mMongo Connection options�[39m
2026-09-24 13:33:03 �[32minfo�[39m: �[32m{�[39m
�[32m  "bufferCommands": false�[39m
�[32m}�[39m
🤖:  ✅  Connected to Database
🤖:  ✅  Found user in Database
🤖:  ✅  Deleted 1 convos & 2 messages
🤖:  ✅  Deleted user from Database
🤖: global teardown has been started
2026-09-24 13:33:03 �[32minfo�[39m: �[32mMongo Connection options�[39m
2026-09-24 13:33:03 �[32minfo�[39m: �[32m{�[39m
�[32m  "bufferCommands": false�[39m
�[32m}�[39m
🤖:  ✅  Connected to Database
🤖:  ⚠️  User not found in Database
  1 failed
    [chrome] › e2e/lighthouse/load.spec.ts:10:5 › serial database latency stays within web-vitals budgets 

Open the full run

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review handoff for exact remote head 5634f3fa082f141a32ccabd53db81cc071ab3d5a. CI repair: route tests now provide the new private-text view/ingress factories; ordinary conversations bypass the owner-only provider, avoiding auth-context work and fetch setup on the Lighthouse transcript. New regression test covers the no-private-text fast path. Local verification: seven affected API suites (59 tests), two client suites (11 tests), client TypeScript, client production build, and staged static checks passed. Protected owner-view browser recheck and CI for this head are pending. No inline review threads were present on the previous head.

@danny-avila

Copy link
Copy Markdown
Collaborator

@codex review the latest head

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-02T15:41:11.109991Z 7b9013e Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5634f3fa08

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/data-schemas/src/schema/message.ts
Comment thread client/src/components/Chat/Messages/PrivateText.tsx Outdated
Comment thread packages/data-schemas/src/methods/message.ts
Comment thread client/src/components/Chat/Messages/PrivateText.tsx Outdated
@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review handoff for exact remote head 28ed3d1ea83c8fc29d498f43c21f8b5aa9894ac8. All four actionable Codex threads were fixed and replied to with this commit: imported/bulk/fork sidecar sanitation, bounded concurrent incremental owner fetches with scoped revision reuse, atomic stale-ciphertext removal on canonical edits (and local revision invalidation), and normal user-message presentation for display-only originals.\n\nFocused checks passed: 149 Mongo-backed schema tests and data-schemas TypeScript/build; 27 client edit, protected display, and ordinary-chat tests plus client TypeScript/build; 288 fork/import/agent-controller tests; the protected browser submit/retry/reload/share/deletion flow, including a normal dir=auto container; the real API build; and staged static checks. The previous PR head was green across all 31 non-skipped CI checks. CI including Lighthouse for this new head is pending; I did not rerun local Lighthouse. The final browser test passed against the current UI and a schema build with identical runtime behavior prior to the ES2019-compatible null-edit check. No independent review has arrived for this new head yet.

@danny-avila

Copy link
Copy Markdown
Collaborator

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 28ed3d1ea8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread api/server/routes/agents/chat.js Outdated
Comment thread packages/data-schemas/src/methods/message.ts Outdated
Comment thread client/src/components/Chat/Messages/PrivateText.tsx Outdated
Comment thread client/src/hooks/Chat/useChatFunctions.ts
@danny-avila danny-avila added 🗺️ Moderation Sec codegraph: the taxonomy area this belongs to (classifier, confidence ≥ 0.9) 🛡️ security review labels Sep 25, 2026
# Conflicts:
#	api/server/controllers/agents/__tests__/request.partialDisconnect.spec.js
#	api/server/controllers/agents/__tests__/request.resumeMetadata.spec.js
#	client/src/locales/en/translation.json
@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review handoff for exact remote head 27bd2242a1f4b9ff09296214136e4e9cbdc35a88. Brought the branch up to 696ebedce04c7804dcf18920c654cfa173d2ec80 (origin/dev at merge time), resolving three conflicts without rewriting the reviewed commits. This head fixes Codex's four actionable findings: filters before ban/limit denials with a safe unsupported-content fallback and encrypted denial persistence; Stop verifies the already-persisted sidecar instead of destroying it; owner-view failures have an explicit localized retry; browser submission diagnostics log identifiers only. Focused JS tests (255), Mongo message tests (172), PII transformer tests (31), UI tests (28), all changed TS workspaces' typechecks, backend and frontend builds, staged static checks, and the protected browser submit/retry/reload/share/delete flow passed locally. PR-wide static and CI including Lighthouse are running on this exact SHA. No review of this SHA has arrived yet.

@danny-avila

Copy link
Copy Markdown
Collaborator

@codex review the latest head

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 27bd2242a1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread api/server/routes/agents/index.js Outdated
Comment thread api/server/routes/agents/index.js
Comment thread client/src/components/Chat/Messages/PrivateText.tsx Outdated
@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Exact-head review handoff: a036847b15ee623efb0d2a04cb9a4c954c9d9c98. This head loads policy before text-bearing Agent ban denials (including queued turns), carries the private revision from preliminary and created job metadata through Stop, preserves older revisionless rows through insert-only storage, and retries early missing owner reads once after turn completion. Focused Agent-route, ban, Mongo, job-store and UI tests passed; changed-workspace TypeScript, builds, PR-wide static checks, and a real-browser protected conversation passed. Please review this exact SHA; previous-head review findings are answered on their threads.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

New exact-head review handoff: 0cf0686ec6c426cbafe52842c89e38eaf8b61831. The protected-message lifecycle fix remains on this head. This follow-up only teaches the partial-disconnect controller test its new preliminary metadata pass-through and formats the new job-store regression for CI. The formerly failing partial-disconnect suite (4/4) and current-dev PR-wide static checks pass locally. Please review this exact SHA; earlier reviews covered previous heads.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Exact-head review handoff: 7696f792b40d2a643dfe7bb7fd337c7f80af2630. The opt-in protected-message fixes remain unchanged. This final follow-up completes the legacy partial mock in the 160-case resume-metadata controller suite. Its two focused early-job cases pass, as do the 4 partial-disconnect tests, current-dev PR-wide static checks, package API TypeScript, protected-message Mongo/job-store/route/UI suites, and the focused real-browser flow. CI is rerunning against this head; please assess this exact SHA rather than earlier heads.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Exact-head review handoff: 22734756b250eb9aad664dd2dcf1a64658163f71. CI uncovered a tenant Stop test stub that returned a flag instead of the saved message identity. The fixture now returns the persisted identity and asserts the insert-only Stop prerequisite. All 48 tenant stream/Stop tests and PR-wide static checks pass locally. The production protection flow is unchanged from the previous head; CI and independent review must assess this exact SHA.

@danny-avila

Copy link
Copy Markdown
Collaborator

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 22734756b2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread api/server/middleware/denyRequest.js
Comment thread packages/api/src/protection/private/submission.ts
Comment thread client/src/components/Chat/ChatView.tsx Outdated
# Conflicts:
#	api/app/clients/BaseClient.js
#	api/server/controllers/agents/request.js
#	api/server/routes/agents/__tests__/abort.spec.js
#	api/server/routes/agents/index.js
#	api/server/routes/messages.js
#	client/src/components/Chat/ChatView.tsx
#	client/src/locales/en/translation.json
#	e2e/setup/fake-model.js
#	packages/data-schemas/src/methods/message.ts
@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Exact-head review handoff: 077e21df48c3c8c6df3f349ea2a0cbbed8c1532d. This head integrates dev@d3d9bc9703295241452edf1bf4760576ce0e3db3 without rewriting history. It preserves dev's centralized App-budget/versioned writes and stopped-reply stamping. The generated-placeholder fix now reaches the actual model-call guard and restored history, with exact trusted-token scope and regressions for forged tokens, mismatched revisions, adjacent raw secrets and independent instruction policies. Local provider-policy (216), Agent/BaseClient/denial/Stop/search (546), Mongo privacy (11), and owner/export UI (24) tests pass; affected typechecks, builds and PR-wide static checks pass. The strengthened email-plus-hex browser flow and current-head CI are being verified. Independent frozen-head review is running in parallel.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Exact-head review handoff: fad416b74e77882023cb866e8425748591cabccf. This head includes current dev and fixes both independent-review P2 findings: protected created frames now wait for durable user/conversation storage, and trusted generated tokens reach Google/Vertex native URL-context and native share preflight. Anonymous shared responses still omit owner metadata; raw surrounding text and untrusted imports remain inspected. New startup/provider/native-copy regressions, typechecks, PR-wide static gates, and both real-browser privacy flows pass. Fresh independent frozen-head review is running alongside CI. Please assess this exact SHA.

@danny-avila

Copy link
Copy Markdown
Collaborator

@codex review the latest head, final review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: fad416b74e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/api/src/protection/private/submission.ts Outdated
Comment thread client/src/components/Chat/Messages/PrivateText.tsx Outdated
Comment thread api/app/clients/BaseClient.js Outdated
@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Head: 4d2804ec0a8f54c6026f928dee0db87d761a3e48

Integrated dev@3699557010979b196e96868bec0e9eb905ae3fb9 without rewriting history. Stop now uses persisted-row protection, not placeholder syntax. Owner reads use an isolated shared React Query client with inactive lifetime zero. Protected turns commit and announce created only after exact native-input admission.

Agent/BaseClient/Stop regressions: 461 passed. API and client typechecks passed before the final hook-dependency cleanup. Query/policy regressions, browser build, final checks and independent frozen-head review are running.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Head: e8621b7caf30d1b4d780e8fbfff640b854310ce3

Independent review of the preceding head found two P2 defects. Both are fixed here: captured turns without a persistence gate fail before model invocation; screenshots pin the rendered conversation and DOM node across mounting, cloning, encoding and download. No findings rejected.

Policy: 220 tests passed. Agent/BaseClient/Stop: 465 passed. Screenshot/owner/export/rendering: 49 passed before the final nullability-only cleanup. API/client types and API/browser builds passed. Browser privacy and safe PNG export: 3 passed. Final UI/static checks, CI, Lighthouse and fresh independent review are being collected.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Head: 6a30e2ae0d5ff901826a2109b98f35df43070d5f

The preceding independent review found three P2 defects. This head gates automatic extraction on admitted protected persistence, passes exact canonical token trust into memory inspection, and retains server-only token provenance through native fork/duplicate/share copies. Untrusted imports and canonical overwrites strip it; ordinary reads and public/export DTOs exclude it. No findings rejected.

Policy/memory: 188 tests passed. Agent/BaseClient/native-copy/import: 628 passed. Mongo privacy/share: 117 passed. API/data-schemas types and builds passed. Real-browser native copies, follow-up model calls, sharing and repeated duplication passed. Final checks, CI and independent review are running.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Head: c7dee4f016c3b0eaf84c0ae753ff20e25af88260

Carries the memory-admission and native-copy token-provenance fixes from 6a30e2ae0, plus a CI fixture repair. The concurrent Stop test now awaits the production unique index and verifies one row, matching the core message-writer fixture. No production behavior changed in the final commit.

API policy/memory: 188 passed. Agent/BaseClient/copy/import: 628 passed. Mongo message/privacy/share: 305 passed. Changed workspace types, builds and touched-file quality checks passed. Native-copy browser scenario passed. Final-head CI and review are being collected. The prior head passed Lighthouse CI; its review does not cover this new SHA.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Head: fea0d542ffec641043fa4225633ac1525d04c3fe
Base/merge-base: abab0d3c6d48dac3c58538ffa404676b9e477440

Integrated latest dev without rewriting history. Protected admission is now irrevocable across terminal recovery; rejected turns cannot create error history or be revived by a later write. Immediate title inference waits for the same admitted protected persistence, including cancellation and write failure.

Merged-head policy/memory/share tests: 388 passed. Agent/BaseClient/recovery/native-copy/import tests: 808 passed. Four shared package builds passed. The real-browser rejected-history regression passed before the dev merge. Final types/static/storage/browser gates, CI and fresh exact-head independent review are running. No findings rejected or current-head clean-review result claimed.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Head: 7b9013e45a949e3aa1d44485c79d024d0539baed
Base/merge-base: abab0d3c6d48dac3c58538ffa404676b9e477440

Fixes two P2 findings from the preceding review. Protected persistence waits for every starting root's inspected native input before any root invokes its model. Pre-admission Stop cancels the pending protected writer; ordinary and already-admitted Stop keep their durability behavior. Initial summarization detours fail closed, avoiding model work before admission or parallel-barrier deadlock.

Policy/private/admission/memory: 289 tests passed, including real SDK parallel-root and actual callback-manager regressions. Agent/BaseClient/recovery/Stop: 651 passed. API types passed. Final build/static/browser checks, CI and independent exact-head review are running. No findings rejected.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Reviewed head: 7b9013e45a949e3aa1d44485c79d024d0539baed

Independent review completed with no new findings. All supported prior findings are fixed; none rejected. It revalidated the full diff and lifecycle boundaries, with six dependency-free checks. Dependency-backed verification was run by the implementation workflow, not independently by the reviewer.

Current-head checks: 940 focused tests, five browser scenarios, API types/build and PR-wide static gates passed. Lighthouse CI passed. Six memory E2E CI shards remain running; no failures.

@danny-avila

Copy link
Copy Markdown
Collaborator

@codex review the latest head, final review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Keep them coming!

Reviewed commit: 7b9013e45a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@danny-avila
danny-avila merged commit 73d7046 into dev Oct 2, 2026
45 checks passed
@danny-avila
danny-avila deleted the lia/pii-owner-view branch October 2, 2026 15:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🗺️ Moderation Sec codegraph: the taxonomy area this belongs to (classifier, confidence ≥ 0.9) 🛡️ security review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants