Skip to content

fix(server): derive imported Codex titles from user requests - #10521

Open
Gigioxx wants to merge 2 commits into
pingdotgg:mainfrom
Gigioxx:t3code/reproduce-and-fix-issue-1
Open

Gigioxx wants to merge 2 commits into
pingdotgg:mainfrom
Gigioxx:t3code/reproduce-and-fix-issue-1

Conversation

@Gigioxx

@Gigioxx Gigioxx commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Problem

Importing a Codex session could name the thread <recommended_plugins>, <environment_context>, or an # AGENTS.md instructions heading instead of the user's request, because the title came from the first line of the first user message and Codex prepends injected context blocks there.

Change

Prefer name or threadName when present in the session metadata. Otherwise, skip known leading Codex context blocks and the request heading when deriving the title. Context-only messages are skipped for title selection; imported history stays unchanged. The fix lives in the shared scanner used by onboarding imports. Existing imported threads are not renamed.

Scope and approval

Closes #10513. Maintainer triage confirmed the bug and its cause (first-line title fallback picking up injected Codex preambles): #10513 (comment)

Verification

  • Reproduced before the fix with nine failing regression cases in apps/server/src/project/AgentSessionScanner.test.ts, covering preserved message text, response-only transcripts, empty context, nullable titles, fork metadata, and streamed transcript reads.
  • After rebasing on current main: vp test run src/project/AgentSessionScanner.test.ts in apps/server, 91 of 92 passed. The one failure, excludes sandboxes reached through a symlink into the worktrees dir, is not touched by this PR and fails identically on unmodified main on this macOS machine (temp dir symlink). vp lint and vp fmt --check on both changed files: clean. tsc --noEmit for apps/server: no errors.
  • Not checked: this is a server parsing change, so no browser or client verification was performed.

Original change by GPT-6 via Codex. Rebase and description update by Claude Opus 5.5 via Claude Code.

Note

Fix parseAgentSessionRecords to derive imported Codex titles from user requests

  • Imported Codex transcripts now prefer a saved session name from metadata, otherwise derive a title from cleaned first-user prompt text (first line, up to 100 chars), and fall back to a generic title.
  • Title derivation strips recognized leading instruction, context, plugin, and request-heading preambles before extracting the first line; the original user prompt in the stored message list is never modified.
  • Extended TranscriptRecord schema with nullable optional fields for a saved session name and an alternate thread name in AgentSessionScanner.ts.
  • Added parameterized and integration tests covering preamble removal, markup handling, metadata fallback, truncation, fork metadata, and response-only transcripts.
  • Behavioral Change: existing Codex imports that relied on context markers or request headings as titles now use the cleaned first-line request text instead.

Macroscope summarized 5253a17.

Summary by CodeRabbit

  • Bug Fixes
    • Imported Codex threads now use saved session names when available.
    • Thread titles are derived more accurately from the user’s request when no saved name exists.
    • Removed common prompt instructions, markup, and headings from automatically generated titles.
    • Added handling for additional session metadata title fields.

@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Sep 7, 2026
@macroscopeapp

macroscopeapp Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at 5253a17

Macroscope's review found this PR approvable — The change is a localized fix to imported Codex thread naming, with explicit metadata fallback and well-scoped prompt cleanup while preserving stored message content. Regression tests cover the new title behavior and edge cases without introducing broader runtime or configuration changes.

No code changes detected at d56fb5e. Prior analysis still applies.

You can add or adjust custom eligibility rules. Learn more.

@coderabbitai

coderabbitai Bot commented Sep 7, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: pingdotgg/t3code/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 0f48a90f-8c09-4efe-8f27-3e6c99dd8d96

📥 Commits

Reviewing files that changed from the base of the PR and between 5253a17 and 2fd54a9.

📒 Files selected for processing (2)
  • apps/server/src/project/AgentSessionScanner.test.ts
  • apps/server/src/project/AgentSessionScanner.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

Codex session imports now use saved session titles when available. Otherwise, they derive titles from cleaned first-user-message text. The parser falls back to “Imported thread” when neither source provides a title.

Changes

Codex imported thread title derivation

Layer / File(s) Summary
Title resolution
apps/server/src/project/AgentSessionScanner.ts
The transcript schema accepts name and threadName. Codex metadata titles take precedence. Prompt-derived titles remove recognized preambles, use the first line, and truncate it to 100 characters.
Title derivation validation
apps/server/src/project/AgentSessionScanner.test.ts
Tests cover saved metadata titles, fork prompts, cleaned Codex prompts, fallback behavior, and title truncation. They also verify that imported message text remains unchanged.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix · Severity of issue fixed: Low

Suggested reviewers: t3dotgg

Merge Risk: ⚪ Minimal · up to 2fd54

Imported Codex threads now prefer saved names or cleaned request titles while preserving history. No actionable merge-blocking issue is identified; merge after normal checks pass.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 2fd54

Saved session names can now produce unusually large thread titles, increasing stored metadata and the work required to display or search threads. Existing import permissions and thread ownership checks remain in place; no privilege escalation or executable-content path was established.

Retained concerns

  • Low · security · inferred: A writable Codex transcript can now supply an oversized metadata title that bypasses the former 100-character derived-title cap. The observed creation contract accepts it, and shared title-search consumers process the full string. This can increase persistent metadata and client resource consumption, bounded by the existing transcript-reading budget. Actual denial of service was not demonstrated.
Security review details

Security Blast Radius

  • inferred — The identified exposure requires control of metadata in a local transcript that passes workspace matching and is selected for import. Its demonstrated reach is thread metadata and associated client display/search consumers; broader tenant or service exposure was not established. Production reading rejects selected history exceeding its aggregate 32 MiB budget.

Security Findings and Attack Paths

  • observed — The inspected sidebar inserts titles as React text, and desktop notifications use them as notification body text. Command-palette actions target environment and thread identifiers, not title content. These sinks do not establish an executable-content or authority-bearing title path.

Trust Boundaries and Controls

  • observed — Before importability, the scanner checks transcript workspace identity. The importer rejects cross-project thread conflicts and incompatible existing provider bindings. The changed title does not supply inputs to these controls.

Resilience and Maintainability Implications

  • observed — Import ordering remains binding installation, missing-thread creation, missing-history import, then source recording. Existing checks support repeated imports and protect newer bindings. Failures are caught per transcript, but atomic rollback was not established; no title-specific validation failure was found in the inspected contract.

Hardening Proposals

  • proposed — Apply an explicit size policy to imported metadata titles before thread creation, preserving full transcript content separately. A consistent title limit would contain metadata amplification across providers.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Issue #10513 requires imported Codex titles to use saved session metadata when available, or derive the title from the user request after excluding injected context. The scanner now prefers trimmed `n…
Out of Scope Changes check ✅ Passed The changes stay within issue #10513. They update the shared session scanner and its tests to correct imported Codex title selection. The changes preserve imported history and do not rename existing t…
Title check ✅ Passed The title clearly and concisely describes the main change: deriving imported Codex titles from user requests.
Description check ✅ Passed The description includes the required Problem, Change, Scope and approval, and Verification sections. It explains the bug, implementation, issue approval, test results, known unrelated failure, and un…
  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@cursor

cursor Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@Gigioxx
Gigioxx force-pushed the t3code/reproduce-and-fix-issue-1 branch from d56fb5e to 2fd54a9 Compare October 1, 2026 04:10

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews size:S 10-29 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: Imported Codex tasks use <recommended_plugins> as their titles

2 participants