Conversation
This comment has been minimized.
This comment has been minimized.
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This PR adds a cross-environment transcript export path that transfers full thread history, tool output, and saved context through a new authenticated endpoint and attachment workflow. The new multi-layer capability has sensitive-data and environment-boundary implications beyond a small isolated fix. Notes:
You can add or adjust custom eligibility rules. Learn more. |
|
Note This comment is posted by Julius' dot The composer currently rejects cross-environment thread drops; this adds a new transcript-export endpoint and turns those drops into saved file attachments. That workflow needs prior maintainer approval of direction and scope, which is not linked or present in this submission. Please discuss the cross-environment snapshot behavior first, then provide before/after interaction evidence for the loading, attachment, and destination-switch flow; the description explicitly says no browser pass or media was obtained. Closing this submission for reconsideration once those gaps are addressed. |
What changed
Dropping a sidebar thread into a composer on another environment now attaches a saved transcript file. The destination agent can read it through the existing file attachment path, including after the source disconnects. Same-environment drops keep their live thread references.
Why
A thread ID from the source server is not readable on the destination server. The client now reads the source through an authenticated HTTP endpoint that preserves the complete visible timeline, inherited history, tool output, and saved text context. Normal UI history reads are bounded and strip tool details, so they cannot provide this export. The transfer uses existing connection authentication, file limits, upload handling, and draft preparation guards. Results are discarded if the destination draft changes while loading. The source rejects timeline JSON above the file attachment limit before transfer; the client still checks the complete file size.
Validation and limits
UI verification
The native Browser panel could not reach the isolated loopback dev server: navigation returned ERR_CONNECTION_REFUSED, while a local HTTP check returned 200. No browser pass or before/after media is claimed.
Checklist
Model: GPT-6 Astra. Harness: Codex. Independent audit: Claude Opus 5.5 via T3 delegation.