Send stable Idempotency-Key headers and drop the made-up opencode profile - #40
Merged
Merged
Conversation
…file OrgX now replays a write repeated with the same Idempotency-Key, so a retried POST no longer creates a duplicate. - attentionBridge: attention creates and acks already carried a deterministic idempotency_key in the body (session + request + question index for creates, decision + state for acks). It is now also sent as the Idempotency-Key header. - orgx-work-graph-reconcile: POST /api/client/work-graph/reports sent no key. Mirror the Codex plugin: key on the digest of the exact report body and send the matching X-OrgX-Payload-Digest header. - continuityHealth: the health contract claimed profile 'opencode' with 33 tools, but the OrgX MCP server has no such profile (unknown profiles fail closed to read-only). Report the profile the endpoint requests (null when it names none) and report unprobed tool/entity counts as null with measurement 'not_probed', matching the Codex plugin. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01SeH94jeHnhDbgzKm6yHqZ9
hopeatina
marked this pull request as ready for review
October 2, 2026 14:00
hopeatina
pushed a commit
that referenced
this pull request
Oct 2, 2026
Ships #40 (send stable Idempotency-Key headers on attention and Work Graph writes; report the MCP endpoint's real tool profile instead of a made-up opencode one). Versions aligned across package.json, package-lock.json and plugin.manifest.json; the peer test's gateway_version fixture follows the version. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01SeH94jeHnhDbgzKm6yHqZ9
hopeatina
pushed a commit
that referenced
this pull request
Oct 2, 2026
hopeatina
added a commit
that referenced
this pull request
Oct 2, 2026
…le (#41) Ships #40 (send stable Idempotency-Key headers on attention and Work Graph writes; report the MCP endpoint's real tool profile instead of a made-up opencode one). Versions aligned across package.json, package-lock.json and plugin.manifest.json; the peer test's gateway_version fixture follows the version. Co-authored-by: Claude Opus 5.5 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
OrgX now replays a write repeated with the same
Idempotency-Key, so a retried POST no longer creates a duplicate.Changes
src/attentionBridge.ts: attention creates and acks already put a deterministicidempotency_keyin the body. Creates use session + request + question index; acks use decision + state.requestJsonnow also sends that value as theIdempotency-Keyheader. GET polls are unchanged.scripts/orgx-work-graph-reconcile.mjs:POST /api/client/work-graph/reportssent no key. It now follows the Codex plugin:work-graph-report:<sha256 of the exact body>plusX-OrgX-Payload-Digest.src/continuityHealth.ts: the health contract claimedprofile: 'opencode', profile_tools: 33. The OrgX MCP server has noopencodeprofile, and unknown profiles fail closed toread-only. Following the Codex plugin, it now reports the profile named by the endpoint's?profile=, ornullwhen the endpoint names none (the default endpoint names none). Tool and entity counts were hardcoded and never measured. They are now reported asnullwithmeasurement: 'not_probed'. The server's continuity view will therefore show "Tool profile incomplete" and "Entity coverage incomplete" instead of claiming coverage nobody measured. The README line about this was updated.Tests
attentionBridge.test.ts: every write's header equals its bodyidempotency_key. Running the same request twice sends identical keys and bodies. GETs carry no key.orgx-work-graph-reconcile.node-test.mjs: a retry reuses the key and body, the digest header matches, and a different report gets a new key.continuityHealth.test.ts: the profile comes from the endpoint (commander), a malformed endpoint givesnull, and the existing contract test was updated to the not-probed shape.npm run type-check && npm test && npm run build: all pass (vitest 129/129, node tests 13/13).🤖 Generated with Claude Code
https://claude.ai/code/session_01SeH94jeHnhDbgzKm6yHqZ9
Generated by Claude Code