mirror of
https://github.com/openai/codex.git
synced 2026-09-11 20:36:49 +00:00
## Why App widgets need to read resources using the app and account context of the tool call that produced them, including after a thread is restored. ## What changed - Add an optional `originCallId` to `mcpServer/resource/read` requests and return it on successful scoped reads. - Track bounded provenance for successful app tool calls in thread history and use the current tool binding, account link, and app policy when reading the associated widget resource. - Reject missing, mismatched, failed, or ambiguous origins, while keeping app-only tools available for widget reads without exposing them to the model. ## Testing Add app-server coverage for scoped widget reads across both history modes, ephemeral and persistent threads, server restarts, app-only visibility, and invalid origin cases. GitOrigin-RevId: 11eaefc066b2a3b639599e4cbdef680233d150a2
1.6 KiB
Generated
1.6 KiB
Generated