Qualify private provider auth recording and export boundaries - #1484
Merged
Merged
Conversation
5 of 48 tasks
7 of 51 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Provider-auth recording qualification
Extend the existing real Chromium/WebKit callback/public-runtime authentication matrix through production message-storage, timeline recording and SSE recording seams. Each of eight success/denial-retry/cancel/expiry flows now checks full-mode persisted JSONL, persisted-timeline snapshots and real JSON/JSONL/HTML export handlers.
Checks
Cache-Control: no-store.Validation
Scope
No production behaviour or redaction-policy changes. Synthetic provider/test HTTP adapter only; production authentication middleware, historical cards/recordings/backups, arbitrary pasted secrets/tool output, external OTel exporters, live providers, Delegate parity and native MCP acceptance are unqualified. No live credentials/history read, inference, deployment or restart. #1442/#1458 stay open.
Initial wrong broadcaster factory import failed at module load and was corrected. Broad standalone fixture typing needed existing repository ambient declarations, which are now included in its strict check.
Refs #1458.