Skip to content

test: exercise direct browser imports without credentials - #2501

Open
jbeckwith-oai wants to merge 1 commit into
mainfrom
codex/browser-direct-import-regression-2494
Open

test: exercise direct browser imports without credentials#2501
jbeckwith-oai wants to merge 1 commit into
mainfrom
codex/browser-direct-import-regression-2494

Conversation

@jbeckwith-oai

Copy link
Copy Markdown
Contributor
  • I understand that this repository is auto-generated and my pull request may not be merged

Changes being requested

  • Run the existing browser-direct-import Puppeteer fixture in ordinary credential-free ecosystem checks against the actual packed and installed SDK, using its existing native browser ESM import of index.mjs without an import map.
  • Fail promptly on browser page/module-loading errors, reject and abort every off-origin request in non-live mode, and verify that browser API-key protection remains enabled by default with a synthetic credential.
  • Preserve the existing live browser fixture, direct credential-backed invocation, and immutable origin-scoped credential preload.

Verification

  • pnpm build
  • pnpm lint
  • pnpm exec tsc --noEmit
  • npm run tsc in ecosystem-tests/browser-direct-import
  • ./scripts/test tests/ecosystem-cli.test.ts tests/ecosystem-browser-credential-security.test.ts (24 tests)
  • Real headless Chrome against current main: fails immediately with Failed to resolve module specifier "#x509-transport-state" before any API request.
  • Real headless Chrome with only an ignored installed-package simulation of the separate production fix: passes the credential-free native-import and default browser API-key-protection check.
  • Three adversarial review rounds, including dedicated browser credential/network security review; the final two independent two-reviewer rounds were clean.

Additional context & links

@jbeckwith-oai
jbeckwith-oai requested a review from a team as a code owner August 27, 2026 05:58
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 27, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-08-27T06:00:18.374685Z dc39e9a PR opened
🔒 Security Review Completed 2026-08-27T06:01:04.434780Z dc39e9a PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@openai-sdks

openai-sdks Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

OkTest Summary

237/237 SDK tests passed in 8.53s for Node SDK PR #2501.

Test results — 42 files
Test Result Time
tests/chat-completions-complex-body.test.ts ✅ Passed 124ms
tests/chat-completions-create.test.ts ✅ Passed 136ms
tests/chat-completions-stream.test.ts ✅ Passed 100ms
tests/files-content-binary.test.ts ✅ Passed 92ms
tests/files-create-multipart.test.ts ✅ Passed 133ms
tests/files-list-pagination.test.ts ✅ Passed 109ms
tests/initialize-config.test.ts ✅ Passed 116ms
tests/instance-isolation.test.ts ✅ Passed 109ms
tests/models-list.test.ts ✅ Passed 95ms
tests/responses-background-lifecycle.test.ts ✅ Passed 141ms
tests/responses-body-method-errors.test.ts ✅ Passed 223ms
tests/responses-cancel-timeout.test.ts ✅ Passed 232ms
tests/responses-cancel.test.ts ✅ Passed 142ms
tests/responses-compact-retries.test.ts ✅ Passed 187ms
tests/responses-compact.test.ts ✅ Passed 177ms
tests/responses-create-advanced-stream.test.ts ✅ Passed 112ms
tests/responses-create-advanced.test.ts ✅ Passed 145ms
tests/responses-create-disconnect.test.ts ✅ Passed 1.081s
tests/responses-create-errors.test.ts ✅ Passed 135ms
tests/responses-create-malformed-api-responses.test.ts ✅ Passed 133ms
tests/responses-create-retries.test.ts ✅ Passed 131ms
tests/responses-create-stream-failures.test.ts ✅ Passed 115ms
tests/responses-create-stream-timeout.test.ts ✅ Passed 2.131s
tests/responses-create-stream-wire.test.ts ✅ Passed 2.049s
tests/responses-create-stream.test.ts ✅ Passed 59ms
tests/responses-create-terminal-states.test.ts ✅ Passed 162ms
tests/responses-create-timeout.test.ts ✅ Passed 197ms
tests/responses-create.test.ts ✅ Passed 113ms
tests/responses-delete.test.ts ✅ Passed 105ms
tests/responses-input-items-errors.test.ts ✅ Passed 136ms
tests/responses-input-items-list.test.ts ✅ Passed 139ms
tests/responses-input-items-options.test.ts ✅ Passed 92ms
tests/responses-input-tokens-count-timeout.test.ts ✅ Passed 208ms
tests/responses-input-tokens-count.test.ts ✅ Passed 167ms
tests/responses-malformed-inputs.test.ts ✅ Passed 1.629s
tests/responses-not-found-errors.test.ts ✅ Passed 168ms
tests/responses-parse.test.ts ✅ Passed 133ms
tests/responses-retrieve-retries.test.ts ✅ Passed 198ms
tests/responses-retrieve.test.ts ✅ Passed 162ms
tests/responses-stored-method-errors.test.ts ✅ Passed 422ms
tests/retry-behavior.test.ts ✅ Passed 3.133s
tests/sdk-error-shape.test.ts ✅ Passed 205ms

View OkTest run #33044249698

SDK merge (da887fb80794) · head (dc39e9ab2d8b) · base (76b73a9c73aa) · OkTest (2b1bdfd25e98)

@github-actions

Copy link
Copy Markdown
Contributor

Castiron custom code

✅ No new custom-code files detected.

32 mixed files remain; 0 existing customizations changed.

Compared 76b73a9c73aadc39e9ab2d8b. Generated baselines verified.

32 existing customizations unchanged
  • api.md
  • scripts/castiron/README.md
  • scripts/castiron/custom_code_report.py
  • scripts/castiron/test_custom_code_report.py
  • src/client.ts
  • src/resources/audio/transcriptions.ts
  • src/resources/audio/translations.ts
  • src/resources/beta/assistants.ts
  • src/resources/beta/beta.ts
  • src/resources/beta/index.ts
  • src/resources/beta/responses/internal-base.ts
  • src/resources/beta/responses/responses.ts
  • src/resources/beta/threads/index.ts
  • src/resources/beta/threads/runs/index.ts
  • src/resources/beta/threads/runs/runs.ts
  • src/resources/beta/threads/threads.ts
  • src/resources/chat/completions/completions.ts
  • src/resources/chat/completions/index.ts
  • src/resources/conversations/index.ts
  • src/resources/embeddings.ts
  • src/resources/files.ts
  • src/resources/fine-tuning/checkpoints/permissions.ts
  • src/resources/images.ts
  • src/resources/responses/internal-base.ts
  • src/resources/responses/responses.ts
  • src/resources/skills/skills.ts
  • src/resources/skills/versions/versions.ts
  • src/resources/vector-stores/file-batches.ts
  • src/resources/vector-stores/files.ts
  • src/resources/webhooks/index.ts
  • src/resources/webhooks/webhooks.ts
  • tests/lib/data-residency.test.ts

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 33044265342 --repo openai/openai-node \
  --name castiron-custom-code-33044265342-1 --dir /tmp/castiron-custom-code-33044265342-1
git apply --stat /tmp/castiron-custom-code-33044265342-1/custom-code.patch
cat /tmp/castiron-custom-code-33044265342-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin 76b73a9c73aafe11c60a425a82898705f1db966d dc39e9ab2d8bb98f080c3ad1e5921dd88899d8de
python3 scripts/castiron/custom_code_report.py report \
  --base 76b73a9c73aafe11c60a425a82898705f1db966d \
  --head dc39e9ab2d8bb98f080c3ad1e5921dd88899d8de --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-dc39e9ab2d8b
cat /tmp/castiron-custom-code-dc39e9ab2d8b/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant