Codex Responses-Lite moves web_search into additional_tools, which the hosted backend ignores. Keep the classic top-level tools contract for all dedicated Codex web searches and cover GPT-5.6 request shape.
Fixes#7666
The Codex SSE `type:"error"` branch read only top-level `code`/`message`,
so backend rejections emitted under a nested `error` or `response.error`
object collapsed to `Codex error (): Unknown error`, hiding the cause
(e.g. a regional/model-snapshot rejection). `response.failed` similarly
dropped the error code.
Add a shared `extractCodexSseError` that reads top-level, nested `error`,
and `response.error` envelopes, and wire both error paths through it so
the backend code and message survive in `SearchProviderError`. The
existing `web_search_call` requirement is untouched.
Fixes#7200
GPT-5.6 Responses-Lite models receive tool_choice "auto" (the forced
hosted choice is invalid under the lite shape, #5771/#5772), so the model
may answer without invoking the hosted web_search tool. The codex search
parser accepted any non-empty answer, returning a stale completion with
zero sources as a successful search.
callCodexSearch now tracks response.web_search_call.* events (and
web_search_call output items) and throws CodexNoWebSearchError when none
occurred. The candidate chain treats that error as retryable, advancing
default lite models to a non-lite model that forces web_search, and
surfaces a clear failure when the model was explicitly configured.
Fixes#6988
(cherry picked from commit a276cd0b3df1d0d041faf0a63fabcbb884e36a91)
- Implemented a structured web-search query parsing module supporting directives, tokenization, date parsing, and syntax serialization.
- Updated search providers to map query directives and date bounds to native provider parameters and filters.
- Added lenient result constraint post-filtering and configuration settings for enhanced engine routing.
- Added comprehensive unit and integration tests covering query parsing, constraint filtering, and provider-specific request mapping.
- Validated the openai-codex credential origin against the registry storage that supplies the bearer, closing the OAuth-leak path when authStorage and modelRegistry diverge.
- Added a regression test covering the mismatched storage case.
Fixes#6001
- Routed Codex web search through configured Responses base URLs, API keys, and headers while preserving the official OAuth backend.
- Refused OAuth leakage to custom endpoints and stopped explicitly selected providers from silently falling back.
- Added transport, safety, and fail-closed regression coverage.
Fixes#6001
The Responses-Lite rewrite moves tools into an `additional_tools` developer
input and deletes top-level `tools`, but preserved a forced top-level
`tool_choice` (e.g. `{ type: "web_search" }`). With no top-level tools to
validate against, the ChatGPT Codex endpoint rejected the request with
`HTTP 400 Tool choice '…' not found in 'tools' parameter`, and web search
silently fell back to Gemini.
`applyCodexResponsesLiteShape` now sets `tool_choice: "auto"`, matching
codex-rs `build_responses_request`. Classic (non-Lite) Responses requests
keep their forced choice since top-level `tools` remains present.
Fixes#5771
- Added optional FetchImpl fields to compaction, proxy, AI, coding-agent, and mnemopi options.
- Threaded injected fetch implementations through OAuth, discovery, and search/LLM request flows.
- Removed exported hookFetch utility and its package entrypoint from utils.
- Replaced global-fetch test monkeypatching with per-test FetchImpl mocks across test suites.
- Expanded Codex placeholder detection to match common image-reference phrases and punctuation.
- Raised `codex` provider failure when final and streamed text are placeholders and no sources exist.
- Dropped placeholder prose from returned answers while preserving citation sources.
- Centralized OAuth access lifecycle in `AuthStorage`, returning identity metadata and new access-result types.
- Added 60-second skew and strict expiry checks, returning undefined/throws for stale or expired OAuth credentials.
- Removed provider-local token refresh flows from Gemini, Gemini CLI, Antigravity, Kimi, and related OAuth helpers.
- Migrated web-search providers from `AgentStorage` to `AuthStorage` session-aware lookup with `authStorage`/`sessionId`/`signal` flow.
- Replaced `findAnthropicAuth`/DB auth lookup with `buildAnthropicAuthConfig` and explicit base-url override/env fallback ordering.
- Added OpenAI Codex and Gemini web search provider options with updated setup/auth descriptions.
- Updated Codex OAuth flow to refresh near-expiry tokens during web_search and persist the refreshed credentials.
- Plumbed AgentStorage through search orchestrator, scrapers, and fetch paths so providers share session credentials.
- Refactored web provider and credential helpers to accept caller-provided AgentStorage and resolve keys synchronously.
When the Codex Responses API synthesizes an answer without emitting
url_citation annotations, previously-empty sources made cited results
look ungrounded. Add:
- tool_choice: { type: "web_search" } so Codex must call the tool
- markdown-link + bare-URL extraction from the answer as a fallback
that only runs when no structured citations were returned
The model-resolution path is unchanged; getBundledModels already
returns a usable Codex catalog on main.
Closes#724
- Extracted diagnostic target resolution logic into new `resolveDiagnosticTargets()` utility function with glob pattern support.
- Consolidated glob pattern detection and file matching logic by replacing conditional branches with unified utility call.
- Added file existence checking with stat before glob expansion to handle bracket paths as literal targets.
- Added test coverage for bracket path handling in diagnostic target resolution.