Files
oh-my-pi/packages/coding-agent
roboomp b25775ecbc fix(mcp): resolve /launch route collision and thread launchUrl through RPC client
Codex review flagged two P2s the reporter (@DylanBohlender) confirmed:

1. OAuthCallbackFlow#handleCallback checked LAUNCH_PATH BEFORE the
   `pathname !== this.callbackPath` guard, so an OMP config that pinned
   the provider callback at `/launch` (via `oauth.callbackPath` or a
   matching `oauth.redirectUri`) had the launch route eat its
   `/launch?code=...&state=...` redirect and 302 it back to the
   authorization URL instead of resolving the callback. Reorder so
   `callbackPath` resolution wins the collision, and suppress `launchUrl`
   in that case (also when `redirectUri`'s pathname resolves to `/launch`
   even without an explicit `callbackPath` override) so UIs never
   advertise a self-redirecting copy target.

2. RpcClient.login's `open_url` listener called
   `onOpenUrl(req.url, req.instructions)` and dropped `launchUrl`, so SDK
   hosts built on the public helper couldn't surface the truncation-safe
   copy target. Extend the callback signature to
   `(url, instructions?, launchUrl?)` and forward the field — backward
   compatible for existing 1-2 arg consumers.

Regression tests in packages/ai/test/callback-server-launch-route.test.ts:
- callbackPath = /launch: launchUrl is undefined AND a
  `/launch?code=...&state=...` request resolves via the callback template
  (200/HTML), never 302s to the authorize URL.
- redirectUri pathname = /launch (callbackPath default): launchUrl still
  suppressed defensively by the parsed-pathname guard so the base class
  never advertises a colliding launch route even when callers skip the
  MCPOAuthFlow path-derivation.
2026-07-03 08:46:28 +00:00
..
2026-07-03 06:37:14 +02:00
…

@oh-my-pi/pi-coding-agent

Core implementation package for the omp coding agent in the oh-my-pi monorepo.

For installation, setup, provider configuration, model roles, slash commands, and full CLI reference, see:

Package-specific references:

Memory backends

The agent supports three mutually-exclusive memory backends, selected via the memory.backend setting (Settings → Memory tab, or ~/.omp/config.yml):

  • off (default) — no memory subsystem runs.
  • local — existing rollout-summarisation pipeline; writes memory_summary.md and consolidated artifacts under the agent dir.
  • hindsight — talks to a Hindsight server (Cloud or self-hosted Docker), retains transcripts every Nth user turn, recalls memories on the first turn of a session, and exposes retain, recall, and reflect.

Hindsight quickstart

  1. Run a Hindsight server (Cloud or docker run -p 8888:8888 ghcr.io/vectorize-io/hindsight:latest).
  2. Set memory.backend = "hindsight" and hindsight.apiUrl = "http://localhost:8888" (or your Cloud URL).
  3. Optional environment overrides (env wins over settings):
    • HINDSIGHT_API_URL, HINDSIGHT_API_TOKEN — connection
    • HINDSIGHT_BANK_ID, HINDSIGHT_DYNAMIC_BANK_ID, HINDSIGHT_AGENT_NAME — bank addressing
    • HINDSIGHT_AUTO_RECALL, HINDSIGHT_AUTO_RETAIN, HINDSIGHT_RETAIN_MODE — lifecycle
    • HINDSIGHT_RECALL_BUDGET, HINDSIGHT_RECALL_MAX_TOKENS — recall sizing
    • HINDSIGHT_BANK_MISSION, HINDSIGHT_DEBUG

Switching backends mid-session is honoured on the next system-prompt rebuild and the next /memory slash command. Existing users with memories.enabled = true|false are migrated to memory.backend = "local"|"off" exactly once on first launch.