Skip to content

fix(auth): bind X.509 bearer attachment to its mTLS transport - #949

Open
jbeckwith-oai wants to merge 1 commit into
mainfrom
codex/x509-bound-transport-auth
Open

fix(auth): bind X.509 bearer attachment to its mTLS transport#949
jbeckwith-oai wants to merge 1 commit into
mainfrom
codex/x509-bound-transport-auth

Conversation

@jbeckwith-oai

Copy link
Copy Markdown
Contributor

Summary

  • Attach X.509 authorization headers only inside the existing certificate-bound mTLS transport.
  • Preserve trusted-origin validation, lazy token acquisition, caching, refresh, 401 recovery, and closed-client behavior for synchronous and asynchronous clients.
  • Add focused public-entrypoint coverage for cloned transports before and after token caching.

Scope

  • Only the private X.509 transport/authentication path and its existing integration suite.
  • No public API, shared core, Bedrock, residency, diagnostics, or workflow changes.

Verification

  • ./gradlew -Dorg.gradle.java.home=/opt/homebrew/opt/openjdk@21/libexec/openjdk.jdk/Contents/Home :openai-java-client-okhttp:test :openai-java-core:test --tests '*WorkloadIdentityAuthTest' --tests '*WorkloadIdentityHttpClientTest' --tests '*ClientOptionsTest' :openai-java-bedrock:test :openai-java-client-okhttp:lintKotlin :openai-java-example:compileJava :openai-java-example:lintJava --no-daemon
  • 150 tests passed; two intentionally opt-in live tests skipped.
  • Java 8-compatible bytecode (classfile major version 52).
  • Two consecutive clean rounds of independent adversarial correctness, security, and architecture review.

@jbeckwith-oai
jbeckwith-oai requested a review from a team as a code owner August 27, 2026 21:27
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 27, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-08-27T21:28:48.567213Z 6562d78 PR opened
🔒 Security Review Completed 2026-08-27T21:29:31.754525Z 6562d78 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@openai-sdks

openai-sdks Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

OkTest Summary

237/237 SDK tests passed in 18.007s for Java SDK PR #949.

Test results — 42 files
Test Result Time
tests/chat-completions-complex-body.test.ts ✅ Passed 193ms
tests/chat-completions-create.test.ts ✅ Passed 811ms
tests/chat-completions-stream.test.ts ✅ Passed 556ms
tests/files-content-binary.test.ts ✅ Passed 171ms
tests/files-create-multipart.test.ts ✅ Passed 298ms
tests/files-list-pagination.test.ts ✅ Passed 352ms
tests/initialize-config.test.ts ✅ Passed 239ms
tests/instance-isolation.test.ts ✅ Passed 118ms
tests/models-list.test.ts ✅ Passed 167ms
tests/responses-background-lifecycle.test.ts ✅ Passed 317ms
tests/responses-body-method-errors.test.ts ✅ Passed 523ms
tests/responses-cancel-timeout.test.ts ✅ Passed 256ms
tests/responses-cancel.test.ts ✅ Passed 445ms
tests/responses-compact-retries.test.ts ✅ Passed 391ms
tests/responses-compact.test.ts ✅ Passed 255ms
tests/responses-create-advanced-stream.test.ts ✅ Passed 643ms
tests/responses-create-advanced.test.ts ✅ Passed 1.252s
tests/responses-create-disconnect.test.ts ✅ Passed 1.126s
tests/responses-create-errors.test.ts ✅ Passed 414ms
tests/responses-create-malformed-api-responses.test.ts ✅ Passed 322ms
tests/responses-create-retries.test.ts ✅ Passed 801ms
tests/responses-create-stream-failures.test.ts ✅ Passed 193ms
tests/responses-create-stream-timeout.test.ts ✅ Passed 269ms
tests/responses-create-stream-wire.test.ts ✅ Passed 7.554s
tests/responses-create-stream.test.ts ✅ Passed 188ms
tests/responses-create-terminal-states.test.ts ✅ Passed 448ms
tests/responses-create-timeout.test.ts ✅ Passed 249ms
tests/responses-create.test.ts ✅ Passed 231ms
tests/responses-delete.test.ts ✅ Passed 292ms
tests/responses-input-items-errors.test.ts ✅ Passed 358ms
tests/responses-input-items-list.test.ts ✅ Passed 493ms
tests/responses-input-items-options.test.ts ✅ Passed 511ms
tests/responses-input-tokens-count-timeout.test.ts ✅ Passed 328ms
tests/responses-input-tokens-count.test.ts ✅ Passed 283ms
tests/responses-malformed-inputs.test.ts ✅ Passed 5.994s
tests/responses-not-found-errors.test.ts ✅ Passed 444ms
tests/responses-parse.test.ts ✅ Passed 707ms
tests/responses-retrieve-retries.test.ts ✅ Passed 330ms
tests/responses-retrieve.test.ts ✅ Passed 227ms
tests/responses-stored-method-errors.test.ts ✅ Passed 1.015s
tests/retry-behavior.test.ts ✅ Passed 3.817s
tests/sdk-error-shape.test.ts ✅ Passed 438ms

View OkTest run #33118230167

SDK merge (9980e686117f) · head (6562d78b9818) · base (9684d5255f5a) · OkTest (2b1bdfd25e98)

@github-actions

Copy link
Copy Markdown
Contributor

Castiron custom code

✅ No new custom-code files detected.

53 mixed files remain; 0 existing customizations changed.

Compared 9684d5255f5a6562d78b9818. Generated baselines verified.

53 existing customizations unchanged
  • openai-java-core/src/main/kotlin/com/openai/models/audio/AudioResponseFormat.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionMessageFunctionToolCall.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionToolMessageParam.kt
  • openai-java-core/src/main/kotlin/com/openai/models/embeddings/Embedding.kt
  • openai-java-core/src/main/kotlin/com/openai/models/embeddings/EmbeddingCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseFunctionToolCall.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseFunctionWebSearch.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseInputItem.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseTextConfig.kt
  • openai-java-core/src/main/kotlin/com/openai/models/videos/Video.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/BetaServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/BetaServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/ResponseServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/ResponseServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/WebhookServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/WebhookServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/audio/TranscriptionServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/chat/ChatCompletionServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/finetuning/checkpoints/PermissionServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/BetaService.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/BetaServiceImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/ResponseService.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/ResponseServiceImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/WebhookService.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/WebhookServiceImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/audio/TranscriptionServiceImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/chat/ChatCompletionService.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/finetuning/checkpoints/PermissionServiceImpl.kt
  • openai-java-core/src/test/kotlin/com/openai/models/beta/responses/BetaResponsesServerEventTest.kt
  • openai-java-core/src/test/kotlin/com/openai/models/responses/ResponsesServerEventTest.kt
  • openai-java-core/src/test/kotlin/com/openai/services/async/CompletionServiceAsyncTest.kt
  • openai-java-core/src/test/kotlin/com/openai/services/async/ImageServiceAsyncTest.kt
  • openai-java-core/src/test/kotlin/com/openai/services/async/ResponseServiceAsyncTest.kt
  • openai-java-core/src/test/kotlin/com/openai/services/async/WebhookServiceAsyncTest.kt
  • openai-java-core/src/test/kotlin/com/openai/services/async/audio/TranscriptionServiceAsyncTest.kt
  • openai-java-core/src/test/kotlin/com/openai/services/async/beta/ResponseServiceAsyncTest.kt
  • openai-java-core/src/test/kotlin/com/openai/services/async/beta/ThreadServiceAsyncTest.kt
  • openai-java-core/src/test/kotlin/com/openai/services/async/beta/threads/RunServiceAsyncTest.kt

13 more in the full report.

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 33118257355 --repo openai/openai-java \
  --name castiron-custom-code-33118257355-1 --dir /tmp/castiron-custom-code-33118257355-1
git apply --stat /tmp/castiron-custom-code-33118257355-1/custom-code.patch
cat /tmp/castiron-custom-code-33118257355-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin 9684d5255f5a6b52234ad4dee461300ac2bc9e5a 6562d78b981880fc726d73911e620bfb2567cbbd
python3 scripts/castiron/custom_code_report.py report \
  --base 9684d5255f5a6b52234ad4dee461300ac2bc9e5a \
  --head 6562d78b981880fc726d73911e620bfb2567cbbd --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-6562d78b9818
cat /tmp/castiron-custom-code-6562d78b9818/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant