Skip to content

Share ChatGPT cookies between HTTP and WebSocket transports - #46506

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/6bd6afe16e97cf9758ca7ba207a4e88c969497a4
Sep 18, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/6bd6afe16e97cf9758ca7ba207a4e88c969497a4

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Share ChatGPT cookies between HTTP and WebSocket transports

Why

WebSocket handshakes did not reuse the HTTP cookie store or retain response cookies, so routing cookies such as __oailb were unavailable to subsequent connections.

What changed

  • Reuse the HTTP factory's ChatGPT cookies for secure WebSocket handshakes, preserving explicit Cookie headers and marking generated headers sensitive.
  • Retain allowlisted infrastructure cookies from both successful and rejected upgrades. Keep configured cookies scoped to their factory and exclude account and session cookies from the shared store.
  • Apply HTTPS cookie scope to wss requests, preserving host and path restrictions and excluding insecure ws requests and non-ChatGPT hosts.

Testing

Add HTTP/WebSocket cookie-sharing coverage and local TLS handshake tests for routing-cookie reuse across connectors, rejected-upgrade refreshes, explicit header precedence, cookie scope, session-cookie exclusion, and deletion.

## Why

WebSocket handshakes did not reuse the HTTP cookie store or retain response cookies, so routing cookies such as `__oailb` were unavailable to subsequent connections.

## What changed

- Reuse the HTTP factory's ChatGPT cookies for secure WebSocket handshakes, preserving explicit `Cookie` headers and marking generated headers sensitive.
- Retain allowlisted infrastructure cookies from both successful and rejected upgrades. Keep configured cookies scoped to their factory and exclude account and session cookies from the shared store.
- Apply HTTPS cookie scope to `wss` requests, preserving host and path restrictions and excluding insecure `ws` requests and non-ChatGPT hosts.

## Testing

Add HTTP/WebSocket cookie-sharing coverage and local TLS handshake tests for routing-cookie reuse across connectors, rejected-upgrade refreshes, explicit header precedence, cookie scope, session-cookie exclusion, and deletion.

GitOrigin-RevId: 6bd6afe16e97cf9758ca7ba207a4e88c969497a4
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/6bd6afe16e97cf9758ca7ba207a4e88c969497a4 branch from 4ffe8cd to 12acac2 Compare September 18, 2026 23:17
@copyberry
copyberry Bot merged commit 12acac2 into main Sep 18, 2026
1 check passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/6bd6afe16e97cf9758ca7ba207a4e88c969497a4 branch September 18, 2026 23:17
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 18, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant