[docs] auth: auth: document universal provider-prefix stripping shipped in PR #9005 - #9062
Conversation
…o all providers PR #9005 extended the redundant <provider>/ model-prefix strip (stripRedundantModelPrefixInBody / stripRedundantProviderPrefix) from Copilot-only to every provider route, so an OpenAI-bound LiteLLM-style openai/gpt-6-sol model ID is normalized before forwarding. Prior docs described this normalization as Copilot-specific. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Two documentation inaccuracies should be corrected before approval.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Documents universal provider-prefix normalization introduced by PR #9005.
Changes:
- Clarifies OpenAI model normalization in two authentication guides.
- Adds the
openai/gpt-6-solnormalization example.
| File | Description |
|---|---|
docs/authentication-architecture.md |
Documents provider-agnostic prefix stripping. |
docs/api-proxy-sidecar.md |
Adds OpenAI normalization guidance. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| Since [PR #9005](https://github.com/github/gh-aw-firewall/pull/9005), the | ||
| redundant `<provider>/` prefix strip applied above is unconditional for every |
| redundant-prefix stripping (`stripRedundantModelPrefixInBody` / | ||
| `stripRedundantProviderPrefix` in `containers/api-proxy/model-utils.js`) is |
|
@copilot address review feedback |
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
|
✅ Copilot review passed with no inline comments. @github-actions[bot] Add the |
Documentation PreviewDocumentation has been built for this PR. To view locally:
Built from commit fc46a60 |
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed.
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟 Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "clients2.google.com"See Network Configuration for more information.
|
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...
|
|
✅ Smoke Claude passed
|
|
✅ Build Test Suite completed successfully!
|
|
🚀 Security Guard has started processing this pull request |
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
❌ Smoke Gemini reports failed. Facets need polishing...
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅
|
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
Smoke Test Results
Note: bash tool blocked all curl invocations with "Permission denied and could not request permission from user", so network egress checks (#2, #4) could not be executed. Not all checks passed; skipping label.
|
|
EGRESS_RESULT allow=pass deny=pass ✅ Allowed domain (api.github.com) reachable — Overall status: PASS cc
|
|
Smoke Test: Copilot BYOK (Direct Mode) ✅ PASS
All tests passed.
|
|
Smoke Test: Copilot Engine —
Overall: PASS
|
|
Smoke Test: Services Connectivity
Overall: PASS
|
Smoke Test: Claude Engine Validation
Overall result: PASS
|
Smoke Test: API Proxy OpenTelemetry Tracing — Results
Overall: ✅ All 5 scenarios passed. No unexpected failures detected.
|
Smoke Test
Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "clients2.google.com"See Network Configuration for more information.
|
🏗️ Build Test Suite Results
Overall: 8/8 ecosystems passed — PASS Notes:
|
Chroot Version Comparison Results
Overall: FAILED — Node.js version mismatch between host and chroot environment. Python and Go versions match; the
|

Summary
containers/api-proxy/model-body-rewriter.js,containers/api-proxy/model-utils.js(stripRedundantProviderPrefix),containers/api-proxy/body-handler.js; merged PRs Normalize OpenAI provider-prefixed models in api-proxy #9005, Share OIDC unavailable-response scaffold across provider adapters #9031, Gate task-level model routing behind experimental opt-in #9033, [docs] auth: auth: correct stale host-routing wiring status in awf-config-spec.md #9034; confirmed no currently-open[docs] auth:PR duplicates this finding.docs/authentication-architecture.mdanddocs/api-proxy-sidecar.mdboth described the LiteLLM-style<provider>/modelprefix strip (e.g.copilot/auto→auto) as Copilot-specific. PR #9005 (merged 2026-09-26) made this stripping unconditional for every provider route —stripRedundantProviderPrefix()incontainers/api-proxy/model-utils.jsis generic (compares any<prefix>/against the route's provider name), andstripRedundantModelPrefixInBody()is called frombody-handler.js'stransformRequestBody()for all writable-method requests regardless of provider. This means an OpenAI-bound request with"model": "openai/gpt-6-sol"(as sent by harnesses like Pi) is now normalized togpt-6-solbefore reaching OpenAI, avoiding the opaque upstream400that PR Normalize OpenAI provider-prefixed models in api-proxy #9005 fixed.mainwith dedicated regression coverage (containers/api-proxy/model-body-rewriter-prefix.test.jsincludes an explicitopenai/prefix-stripping test). Also confirmed §13a task-level routing status (PRs Activate task-level model routing in the API proxy server #8966, Wire task-level model routing into the host workflow #8985, Gate task-level model routing behind experimental opt-in #9033, [docs] auth: auth: correct stale host-routing wiring status in awf-config-spec.md #9034) and the OIDC-scaffold refactor (Share OIDC unavailable-response scaffold across provider adapters #9031, internal-only, no doc-facing behavior change) required no further doc changes.Documentation Changes
openai/gpt-6-sol→gpt-6-solexample.Validation
containers/api-proxy/model-utils.js(stripRedundantProviderPrefix, provider-agnostic comparison),containers/api-proxy/model-body-rewriter.js(stripRedundantModelPrefixInBody),containers/api-proxy/body-handler.js(transformRequestBody, unconditional call site with explanatory comment),containers/api-proxy/model-body-rewriter-prefix.test.js(existingopenai/prefix test, confirms shipped behavior).Sources
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
msfeed25.pkgs.visualstudio.comTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.