Share OIDC unavailable-response scaffold across provider adapters - #9031
Conversation
…apters Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The refactor preserves existing adapter behavior and comprehensively tests the centralized state handling.
Review effort: Balanced
Findings: None
What changed in this PR
Centralizes OIDC-unavailable response and health-state handling across API proxy provider adapters.
Changes:
- Adds a shared OIDC unavailable-response scaffold.
- Migrates OpenAI, Anthropic, and Google adapters.
- Tests all requested/configured state combinations.
| File | Description |
|---|---|
containers/api-proxy/oidc-adapter-utils.js |
Adds the shared scaffold helper. |
containers/api-proxy/providers/openai.js |
Uses the helper for pending OIDC responses. |
containers/api-proxy/providers/anthropic.js |
Replaces duplicated response and health logic. |
containers/api-proxy/providers/google-adapter.js |
Replaces duplicated Google OIDC state logic. |
containers/api-proxy/proxy-utils.oidc.test.js |
Covers scaffold states and fallback behavior. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
✅ Copilot review passed with no inline comments. @copilot Add the |
|
| Metric | Base | PR | Delta |
|---|---|---|---|
| Lines | 92.65% | 92.65% | ➡️ +0.00% |
| Statements | 91.13% | 91.13% | ➡️ +0.00% |
| Functions | 89.17% | 89.17% | ➡️ +0.00% |
| Branches | 84.23% | 84.22% | 📉 -0.01% |
📁 Per-file Coverage Changes (2 files)
| File | Lines (Before → After) | Statements (Before → After) |
|---|---|---|
src/nvx/one-shot-adapter.ts |
83.5% → 82.9% (-0.60%) | 80.3% → 79.8% (-0.56%) |
src/log-directory-setup.ts |
96.2% → 100.0% (+3.78%) | 96.3% → 100.0% (+3.71%) |
Coverage comparison generated by scripts/ci/compare-coverage.ts
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...
|
|
✅ Security Guard completed successfully!
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟 Warning Firewall blocked 12 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"
- "accounts.google.com"
- "api.github.com"
- "clients2.google.com"
- "collector.github.com"
- "contentautofill.googleapis.com"
- "github.com"
- "github.githubassets.com"
- "msfeed25.pkgs.visualstudio.com"
- "update.googleapis.com"
- "www.google.com"
- "www.gstatic.com"See Network Configuration for more information.
|
|
✅ Smoke Claude passed Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅ Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "api.github.com"
- "example.com"See Network Configuration for more information.
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅ Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "o205451.ingest.us.sentry.io"See Network Configuration for more information.
|
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
❌ Smoke Gemini reports failed. Facets need polishing... Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "play.googleapis.com"See Network Configuration for more information.
|
|
Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed. Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"
- "github.com"See Network Configuration for more information.
|
|
✅ Build Test Suite completed successfully! Warning Firewall blocked 8 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.nuget.org"
- "bun.sh"
- "dc.services.visualstudio.com"
- "deno.land"
- "dl.deno.land"
- "github.com"
- "releaseassets.githubusercontent.com"
- "repo.maven.apache.org"See Network Configuration for more information.
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
EGRESS_RESULT allow=pass deny=pass ✅ Allowed domain reachable (HTTP 403 from api.github.com — connection succeeded) Overall status: PASS cc Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "api.github.com"
- "example.com"See Network Configuration for more information.
|
|
Smoke Test: Copilot Engine —
Overall: PASS
|
Smoke Test: Copilot BYOK (Direct) ✅✅ MCP Connectivity - PR list verified Status: PASS | Running in direct BYOK mode (COPILOT_PROVIDER_API_KEY) cc:
|
Smoke Test: Cloud Hypervisor + Copilot
Overall: PASS Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"
- "github.com"See Network Configuration for more information.
|
Smoke Test: Claude Engine Validation
Overall result: PASS Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
|
Smoke Test: Services Connectivity
Overall: PASS
|
Security Review: No Security Issues Detected ✅This PR refactors duplicate OIDC error-handling code across provider adapters (Google, Anthropic, OpenAI) into a shared Security Assessment
Non-Security Note: Logic Bug in openai.jsFile: unconfiguredResponseWhen: buildOidcUnavailableScaffold({
requested: oidcConfigured, // ❌ BUG: should be `oidcRequested`
configured: oidcConfigured,The Recommended fix: Change The refactoring is functionally sound aside from this bug, and introduces no new security weaknesses.
|
Chroot Version Comparison Results
Overall: FAILED — Node.js version mismatch between host and chroot environments. The
|
🏗️ Build Test Suite Results
Overall: 8/8 ecosystems passed — ✅ PASS Note: The Java tasks initially failed with All repositories cloned successfully; no CLONE_FAILED cases. Warning Firewall blocked 8 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.nuget.org"
- "bun.sh"
- "dc.services.visualstudio.com"
- "deno.land"
- "dl.deno.land"
- "github.com"
- "releaseassets.githubusercontent.com"
- "repo.maven.apache.org"See Network Configuration for more information.
|
📡 OTel Tracing Smoke Test Results
Overall: ✅ All scenarios pass. No regressions detected in OTEL tracing integration. Minor note (non-blocking): the "Collect OTEL diagnostics" post-step checks Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "o205451.ingest.us.sentry.io"See Network Configuration for more information.
|
|
Upgrade gh-aw and recompile workflows ✅ Warning Firewall blocked 12 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"
- "accounts.google.com"
- "api.github.com"
- "clients2.google.com"
- "collector.github.com"
- "contentautofill.googleapis.com"
- "github.com"
- "github.githubassets.com"
- "msfeed25.pkgs.visualstudio.com"
- "update.googleapis.com"
- "www.google.com"
- "www.gstatic.com"See Network Configuration for more information.
|
openai.js,anthropic.js, andgoogle-adapter.jseach duplicated the same OIDC failure-handling scaffold: compute an unavailable-error message, return a retryableprovider_not_configuredresponse when OIDC was requested but the token isn't ready yet, and expose a matchingunavailableWhenhealth state. Since this is security-critical auth-path logic, keeping three copies in sync on any change to retryability, wording, or the "requested vs configured" distinction was risky.New shared helper
buildOidcUnavailableScaffold({ requested, configured, unavailableMessage, unconfiguredMessage })tocontainers/api-proxy/oidc-adapter-utils.js, returning{ unconfiguredResponseWhen, unavailableWhen }.unavailableMessage; requested + not configured at all → non-retryable response usingunconfiguredMessage(falls back tounavailableMessageif omitted).Adapter updates
providers/openai.js,providers/anthropic.js,providers/google-adapter.jsnow call the helper instead of hand-rolling the message/retryable/health-state logic. Each adapter only supplies its provider-specific wording.Tests
proxy-utils.oidc.test.jscovering all scaffold states (not requested, configured-but-unavailable, requested-but-unconfigured, and message fallback).Behavior and wording per provider are unchanged; only the duplicated scaffold logic moved into one reviewable place.