Skip to content

[docs] auth: auth: document universal provider-prefix stripping shipped in PR #9005 - #9062

Merged
lpcox merged 2 commits into
mainfrom
docs/openai-prefix-strip-shipped-20260927-a4536ceab6b62f6c
Sep 27, 2026
Merged

lpcox merged 2 commits into
mainfrom
docs/openai-prefix-strip-shipped-20260927-a4536ceab6b62f6c

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Summary

Documentation Changes

Validation

  • Implementation/tests checked: containers/api-proxy/model-utils.js (stripRedundantProviderPrefix, provider-agnostic comparison), containers/api-proxy/model-body-rewriter.js (stripRedundantModelPrefixInBody), containers/api-proxy/body-handler.js (transformRequestBody, unconditional call site with explanatory comment), containers/api-proxy/model-body-rewriter-prefix.test.js (existing openai/ prefix test, confirms shipped behavior).
  • Markdown/link review: new paragraphs use the same PR-link convention as surrounding text; no headings, tables, or code fences altered; both files' existing structure preserved.
  • Credential-leakage diff review: diff scanned for key/token/JWT/header/Bearer patterns — none present; only prose and one PR URL added per file.

Sources

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • msfeed25.pkgs.visualstudio.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "msfeed25.pkgs.visualstudio.com"

See Network Configuration for more information.

Generated by Auth Doctor Updater · copilot · auto · 75.1 AIC · ⊞ 11.8K · ◷

…o all providers

PR #9005 extended the redundant <provider>/ model-prefix strip
(stripRedundantModelPrefixInBody / stripRedundantProviderPrefix) from
Copilot-only to every provider route, so an OpenAI-bound LiteLLM-style
openai/gpt-6-sol model ID is normalized before forwarding. Prior docs
described this normalization as Copilot-specific.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions github-actions Bot added ai-generated documentation Improvements or additions to documentation labels Sep 27, 2026
@github github deleted a comment from manamansor Sep 27, 2026
@lpcox
lpcox requested a balanced review from Copilot September 27, 2026 15:45

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Two documentation inaccuracies should be corrected before approval.

Review effort: Balanced
Findings: 2 Low severity

Open (2)
What changed in this PR

Documents universal provider-prefix normalization introduced by PR #9005.

Changes:

  • Clarifies OpenAI model normalization in two authentication guides.
  • Adds the openai/gpt-6-sol normalization example.
File Description
docs/​authentication-architecture.md Documents provider-agnostic prefix stripping.
docs/​api-proxy-sidecar.md Adds OpenAI normalization guidance.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread docs/api-proxy-sidecar.md
Comment on lines +115 to +116
Since [PR #9005](https://github.com/github/gh-aw-firewall/pull/9005), the
redundant `<provider>/` prefix strip applied above is unconditional for every
Comment thread docs/authentication-architecture.md Outdated
Comment on lines +500 to +501
redundant-prefix stripping (`stripRedundantModelPrefixInBody` /
`stripRedundantProviderPrefix` in `containers/api-proxy/model-utils.js`) is
@lpcox

lpcox commented Sep 27, 2026

Copy link
Copy Markdown
Collaborator

@copilot address review feedback

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>

Copilot AI commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

@copilot address review feedback

Addressed in 7b65b3b: updated the Copilot example to say the proxy strips copilot/ and forwards auto, and corrected the helper references to point stripRedundantModelPrefixInBody at model-body-rewriter.js and stripRedundantProviderPrefix at model-utils.js.

Copilot AI requested a review from lpcox September 27, 2026 16:11
@github-actions

Copy link
Copy Markdown
Contributor Author

✅ Copilot review passed with no inline comments.

@github-actions[bot] Add the ready-for-aw label to this PR to trigger agentic CI smoke tests.

@github-actions

Copy link
Copy Markdown
Contributor Author

Documentation Preview

Documentation has been built for this PR.

Download preview artifact

To view locally:

  1. Download the docs-preview-pr-9062 artifact from the workflow run
  2. Unzip and open index.html in your browser

Built from commit fc46a60

@lpcox
lpcox enabled auto-merge (squash) September 27, 2026 17:35
@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓

🔑 BYOK report filed by Smoke Copilot BYOK

@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed.

Cloud Hypervisor + Copilot smoke test by Smoke Cloud Hypervisor

@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅

📡 OTel tracing validated by Smoke OTel Tracing

@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

🔌 Smoke Services — All services reachable! ✅

🔌 Service connectivity validated by Smoke Services

@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • clients2.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "clients2.google.com"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex

@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...

🪪 BYOK (AOAI Entra) report filed by Smoke Copilot BYOK AOAI (Entra)

@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

✅ Smoke Claude passed

Generated by Smoke Claude for #9062

@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

✅ Build Test Suite completed successfully!

Generated by Build Test Suite for #9062

@github-actions

Copy link
Copy Markdown
Contributor Author

🚀 Security Guard has started processing this pull request

@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤

📰 BREAKING: Report filed by Smoke Copilot

@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

❌ Smoke Gemini reports failed. Facets need polishing...

💎 Faceted by Smoke Gemini

@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅

🛡️ Egress verdict from Smoke Copilot Network Isolation

@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...

🔑 BYOK (AOAI api-key) report filed by Smoke Copilot BYOK AOAI (api-key)

@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.

Tested by Smoke Chroot

@github-actions

Copy link
Copy Markdown
Contributor Author

Smoke Test Results

  1. GitHub list_pull_requests: PASS (PR Split model-resolver.test.js into three focused test files #9080)
  2. curl github.com: FAIL (bash tool denied network command execution — could not verify)
  3. Write/read temp file: PASS
  4. curl example.com blocked check: FAIL (same bash permission denial — could not verify)

Note: bash tool blocked all curl invocations with "Permission denied and could not request permission from user", so network egress checks (#2, #4) could not be executed. Not all checks passed; skipping label.

Cloud Hypervisor + Copilot smoke test by Smoke Cloud Hypervisor
Add label ready-for-aw to run again

@github-actions github-actions Bot added the smoke-copilot-network-isolation Copilot network-isolation egress smoke test label Sep 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor Author

EGRESS_RESULT allow=pass deny=pass

✅ Allowed domain (api.github.com) reachable — allowed=200
✅ Non-allowlisted domain (example.com) blocked — OK: example.com was blocked

Overall status: PASS

cc @lpcox

🛡️ Egress verdict from Smoke Copilot Network Isolation
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor Author

Smoke Test: Copilot BYOK (Direct Mode) ✅ PASS

All tests passed.

🔑 BYOK report filed by Smoke Copilot BYOK
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor Author

Smoke Test: Copilot Engine — @lpcox

Overall: PASS

📰 BREAKING: Report filed by Smoke Copilot
Add label ready-for-aw to run again

@lpcox
lpcox deployed to aoai-model September 27, 2026 17:39 — with GitHub Actions Active
@lpcox
lpcox deployed to aoai-model September 27, 2026 17:39 — with GitHub Actions Active
@github-actions

Copy link
Copy Markdown
Contributor Author

Smoke Test: Services Connectivity

  • Redis PING: ✅ PONG
  • Postgres pg_isready: ✅ accepting connections
  • Postgres SELECT 1: ✅ 1

Overall: PASS

🔌 Service connectivity validated by Smoke Services
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor Author

Smoke Test: Claude Engine Validation

Check Status
API ✅ PASS
gh CLI ✅ PASS
File ✅ PASS

Overall result: PASS

Generated by Smoke Claude for #9062 · claude · haiku45 · 30 AIC · ⊞ 4.6K · ◷
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor Author

Smoke Test: API Proxy OpenTelemetry Tracing — Results

# Scenario Result
1 Module Loading ✅ otel.js loaded successfully, isEnabled: true, exports 14 functions (startRequestSpan, setTokenAttributes, setBudgetAttributes, endSpan, endSpanError, shutdown, isEnabled, plus internal test hooks)
2 Test Suite ✅ 3 suites, 68/68 tests passed (0 failed) — covers serialization, fan-out exporters, header parsing, span creation, gen_ai attributes, ProxyAwareOtlpExporter, FileSpanExporter
3 Env Var Forwarding ✅ env-passthrough.ts forwards GITHUB_AW_OTEL_TRACE_ID and GITHUB_AW_OTEL_PARENT_SPAN_ID to the agent; api-proxy-env-config.ts forwards GH_AW_OTLP_ENDPOINTS, OTEL_EXPORTER_OTLP_ENDPOINT, and both trace-context vars to api-proxy
4 Token Tracker Integration ✅ onUsage callback present in token-tracker-http.js as the OTEL hook point
5 OTEL Diagnostics ✅ 1 span exported to otel.jsonl (gh-aw.agent.setup, workflow-level instrumentation). No api-proxy LLM spans present, expected since this smoke test validates code/config paths rather than making live proxied LLM calls

Overall: ✅ All 5 scenarios passed. No unexpected failures detected.

📡 OTel tracing validated by Smoke OTel Tracing
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor Author

Smoke Test

  • 9080: Split model-resolver.test.js into three focused test files
  • 9075: fix(api-proxy): skip Responses custom-tool translation on Chat Completions routes
  • GitHub merged PR review: ✅
  • PR detail lookup: ✅
  • Playwright title check: ✅
  • File write/read: ✅
  • Build (npm ci && npm run build): ✅
  • Overall: PASS

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • clients2.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "clients2.google.com"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor Author

🏗️ Build Test Suite Results

Ecosystem Project Build/Install Tests Status
Bun elysia ✅ 1/1 passed ✅ PASS
Bun hono ✅ 1/1 passed ✅ PASS
C++ fmt ✅ N/A ✅ PASS
C++ json ✅ N/A ✅ PASS
Deno oak N/A 1/1 passed ✅ PASS
Deno std N/A 1/1 passed ✅ PASS
.NET hello-world ✅ N/A ✅ PASS
.NET json-parse ✅ N/A ✅ PASS
Go color ✅ pass ✅ PASS
Go env ✅ pass ✅ PASS
Go uuid ✅ pass ✅ PASS
Java gson ✅ 1/1 passed ✅ PASS
Java caffeine ✅ 1/1 passed ✅ PASS
Node.js clsx ✅ pass ✅ PASS
Node.js execa ✅ pass ✅ PASS
Node.js p-limit ✅ pass ✅ PASS
Rust fd ✅ 1/1 passed ✅ PASS
Rust zoxide ✅ 1/1 passed ✅ PASS

Overall: 8/8 ecosystems passed — PASS

Notes:

  • Bun and Deno were installed via npm install -g bun/npm install -g deno (the official curl | bash installer scripts were blocked by sandbox policy); both installed fine and all tests passed.
  • Java Maven builds required using a writable local repo (-Dmaven.repo.local) because the pre-existing ~/.m2 directory in this environment was root-owned; this is an environment quirk unrelated to the firewall and once worked around, both projects compiled and tested successfully through the Squid proxy.

Generated by Build Test Suite for #9062 · copilot · auto · 45.4 AIC · ⊞ 11.8K · ◷
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor Author

Chroot Version Comparison Results

Runtime Host Version Chroot Version Match?
Python Python 3.12.14 Python 3.12.14 ✅ YES
Node.js v24.21.0 v22.23.2 ❌ NO
Go go1.22.12 go1.22.12 ✅ YES

Overall: FAILED — Node.js version mismatch between host and chroot environment. Python and Go versions match; the smoke-chroot label was not added since not all tests passed.

Tested by Smoke Chroot
Add label ready-for-aw to run again

@lpcox
lpcox disabled auto-merge September 27, 2026 22:59
@lpcox
lpcox merged commit e316798 into main Sep 27, 2026
121 of 125 checks passed
@lpcox
lpcox deleted the docs/openai-prefix-strip-shipped-20260927-a4536ceab6b62f6c branch September 27, 2026 22:59

This branch was successfully deployed

1 active deployment
aoai-model — 7b65b3b2 Deployed Sep 27, 2026 by lpcox via conclusion #1790
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants