Skip to content

πŸ—“οΈ fix: Omit Unavailable OpenID Headers for Scheduled Chats (opt-in) - #83

Open
busla wants to merge 1 commit into
sync/v0.8.8-rc4from
fix/optional-openid-header-placeholders
Open

busla wants to merge 1 commit into
sync/v0.8.8-rc4from
fix/optional-openid-header-placeholders

Conversation

@busla

@busla busla commented Sep 29, 2026

Copy link
Copy Markdown

Summary

Scheduled Chats run with no browser session, so the schedule owner's req.user carries no OpenID tokens. Every endpoint header that uses {{LIBRECHAT_OPENID_ACCESS_TOKEN}} or {{LIBRECHAT_OPENID_ID_TOKEN}} then makes resolveHeaders throw OpenIDReauthRequiredError, and the scheduled occurrence fails before the model is called:

An error occurred while processing the request: OpenID token is expired or unavailable;
re-authentication is required to resolve {{LIBRECHAT_OPENID_ACCESS_TOKEN}}

Seen on apro-sandbox (conversation c0c80ac4-…, 2026-09-28 17:56 UTC). The aprochat LiteLLM endpoints send authorization: Bearer {{LIBRECHAT_OPENID_ID_TOKEN}} and x-openid-access-token, so every scheduled chat on them fails.

How it works

  • Opt-in: set SCHEDULES_OMIT_UNAVAILABLE_OPENID_HEADERS=true. Default behaviour is unchanged.
  • Route: api/server/routes/agents/index.js marks req.user for scheduled fires only (req._isScheduledFire, set by captureScheduleFireContext).
  • createSafeUser carries the marker to every header-resolution site (run, summarization, memory, activity labels, model fetch).
  • resolveHeaders: when the marker is set and the tokens are unavailable, credential placeholders stay unresolved and the whole header is omitted, whether or not the caller strips unresolved placeholders. It never sends a literal placeholder or an empty Bearer . Valid tokens still substitute.
  • Unaffected: interactive requests, and MCP resolution (processMCPEnv), which feeds the schedule MCP preflight and still signals re-authentication.

Deployment note (aprochat)

With the headers omitted, LiteLLM requests fall back to the endpoint apiKey. The LiteLLM-side decision (master key plus a fixed x-github-repo, or a dedicated virtual key with a budget) is tracked in aprochat-config and should land before enabling the flag in prod. AgentCore models still need the user token and remain unsupported in scheduled runs.

Testing

  • packages/api: npx jest src/utils/env.spec.ts src/utils/headers.spec.ts β†’ 170 passed (4 new: throws without the marker; omits credential headers with and without stripUnresolved; still substitutes valid tokens)
  • tsc --noEmit -p packages/api clean; eslint and prettier clean on the changed files

Risk

Opt-in only, and only for verified schedule fires. With the flag on, a scheduled request drops its OpenID credential headers, so the receiving service must authenticate it another way.

πŸ€– Generated with Claude Code

Scheduled Chats fire without a browser session, so `req.user` has no OpenID
tokens. `resolveHeaders` then throws OpenIDReauthRequiredError for any endpoint
header using {{LIBRECHAT_OPENID_ACCESS_TOKEN}} / {{LIBRECHAT_OPENID_ID_TOKEN}},
and every scheduled occurrence on such an endpoint fails before the model call.

With SCHEDULES_OMIT_UNAVAILABLE_OPENID_HEADERS=true, the agents route marks the
user of a scheduled fire, `createSafeUser` carries the marker, and
`resolveHeaders` omits a header whose OpenID credential placeholder cannot be
resolved instead of throwing, whether or not the caller strips unresolved
placeholders. Valid tokens still substitute. Interactive requests and MCP
resolution (`processMCPEnv`, which feeds the schedule MCP preflight) keep
failing closed. Off by default.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

βš™οΈ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 1b4134b4-3f80-4132-ace1-51d16bc0e7db

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • πŸ” Trigger review

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant