Skip to content

fix(composer): read dropped threads across environments - #14255

Closed
Bil0000 wants to merge 4 commits into
pingdotgg:t3code/codex-turn-mappingfrom
Bil0000:t3code/cross-environment-thread-drag
Closed

Bil0000 wants to merge 4 commits into
pingdotgg:t3code/codex-turn-mappingfrom
Bil0000:t3code/cross-environment-thread-drag

Conversation

@Bil0000

@Bil0000 Bil0000 commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

What changed

Dropping a sidebar thread into a composer on another environment now attaches a saved transcript file. The destination agent can read it through the existing file attachment path, including after the source disconnects. Same-environment drops keep their live thread references.

Why

A thread ID from the source server is not readable on the destination server. The client now reads the source through an authenticated HTTP endpoint that preserves the complete visible timeline, inherited history, tool output, and saved text context. Normal UI history reads are bounded and strip tool details, so they cannot provide this export. The transfer uses existing connection authentication, file limits, upload handling, and draft preparation guards. Results are discarded if the destination draft changes while loading. The source rejects timeline JSON above the file attachment limit before transfer; the client still checks the complete file size.

Validation and limits

  • 116 focused tests pass across HTTP permissions and history export, remote authentication and credential refresh, transcript files, composer context, attachment upload, and contracts.
  • The Opus audit size fix adds a multibyte oversized-export regression check; focused endpoint and contract tests and server/web type checks pass.
  • Server, web, mobile, and client-runtime type checks pass. Targeted lint and formatting pass; existing composer lint warnings remain.
  • This is a snapshot. Later source messages and source attachment bytes are not copied. The source server must include the new endpoint, and normal attachment limits apply.

UI verification

The native Browser panel could not reach the isolated loopback dev server: navigation returned ERR_CONNECTION_REFUSED, while a local HTTP check returned 200. No browser pass or before/after media is claimed.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Model: GPT-6 Astra. Harness: Codex. Independent audit: Claude Opus 5.5 via T3 delegation.

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Sep 29, 2026
Comment thread apps/web/src/lib/threadContextAttachment.ts
Comment thread packages/client-runtime/src/state/orchestration.ts Outdated
@macroscopeapp

This comment has been minimized.

@macroscopeapp

macroscopeapp Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds a cross-environment transcript export path that transfers full thread history, tool output, and saved context through a new authenticated endpoint and attachment workflow. The new multi-layer capability has sensitive-data and environment-boundary implications beyond a small isolated fix.

Notes:

  • No code objects were reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

Comment thread apps/web/src/components/chat/ChatComposer.tsx
Comment thread apps/server/src/orchestration-v2/http.ts

Copy link
Copy Markdown
Member

Note

This comment is posted by Julius' dot

The composer currently rejects cross-environment thread drops; this adds a new transcript-export endpoint and turns those drops into saved file attachments. That workflow needs prior maintainer approval of direction and scope, which is not linked or present in this submission. Please discuss the cross-environment snapshot behavior first, then provide before/after interaction evidence for the loading, attachment, and destination-switch flow; the description explicitly says no browser pass or media was obtained. Closing this submission for reconsideration once those gaps are addressed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L 100-499 changed lines (additions + deletions). vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants