fix(live): keep query parameters out of WebSocket endpoint paths - #3972
Conversation
Castiron custom code✅ No new custom-code files detected. 47 mixed files remain; 3 existing customizations changed. Compared
44 existing customizations unchanged
4 more in the full report. A changed generated baseline means this report cannot reliably identify which handwritten lines changed. Inspect the custom-code diffDownload the exact patch produced by this run (requires repository access): gh run download 36343414524 --repo openai/openai-python \
--name castiron-custom-code-36343414524-1 --dir /tmp/castiron-custom-code-36343414524-1
git apply --stat /tmp/castiron-custom-code-36343414524-1/custom-code.patch
cat /tmp/castiron-custom-code-36343414524-1/custom-code.patchOr reproduce it from an SDK checkout containing the vendored reporter: git fetch --no-tags origin f7bd4a703cad904e4f5d91ec9d7abac70d8c0bd6 652ab1677ca3e6b57bcea95e11b96c7f78f23b0b
python3 scripts/castiron/custom_code_report.py report \
--base f7bd4a703cad904e4f5d91ec9d7abac70d8c0bd6 \
--head 652ab1677ca3e6b57bcea95e11b96c7f78f23b0b --fetch --require-head-hash --public \
--out /tmp/castiron-custom-code-652ab1677ca3
cat /tmp/castiron-custom-code-652ab1677ca3/custom-code.patchThis is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR. |
jbeckwith-oai
left a comment
There was a problem hiding this comment.
Reviewed 6665a3e against a5a6f80. No blocking findings in this stacked diff.
All six sync/async primary, fork and sideband URL builders now append the endpoint before the query while retaining path-template escaping. The 12 loopback cases exercise role-specific paths, special-character session IDs, base/extra query parameters, sideband graceful_close, caller-owned session.start, event correlation and clean shutdown.
Validation: 192 controlled cases using the exact extracted Live URL methods passed with installed HTTPX 0.28.1 and synthetic client/path-template fixtures; all four changed Python files compile in memory. These are isolated URL-method probes, not a local SDK suite. Exact-head hosted Python 3.10/3.14, HTTPX2, lint/build and Castiron baseline checks passed; no live API calls.
Merge ordering: this remains stacked on #3971. Retarget it to main after #3971 merges and confirm the resulting main-based checks before merging this PR.
Stacked on #3971, which fixes base URL normalization. Once that is merged, this PR can be retargeted to main.
Live WebSocket primary, fork and sideband managers appended their endpoint after the base URL query. For example, /v1/customer?tenant=sample dialed /v1/customer instead of the Live endpoint. Append the path before the query in all six sync/async managers.
Tests cover the actual WebSocket upgrade, preserved query parameters and escaped session IDs, caller-initiated primary and fork starts, immediate sideband events without waiting for session.started, follow-up updates and clean close.
Validation: all six query cases failed and six plain cases passed before the fix. After it, all 363 affected tests and 12 base URL tests passed on both Pydantic v1 and v2. Full Ruff, mypy and Pyright passed. No hosted-service or stored-fork-eligibility claims.