Repository navigation
Share ChatGPT cookies between HTTP and WebSocket transports - #46506
Merged
copyberry[bot] merged 1 commit intoSep 18, 2026
Conversation
## Why WebSocket handshakes did not reuse the HTTP cookie store or retain response cookies, so routing cookies such as `__oailb` were unavailable to subsequent connections. ## What changed - Reuse the HTTP factory's ChatGPT cookies for secure WebSocket handshakes, preserving explicit `Cookie` headers and marking generated headers sensitive. - Retain allowlisted infrastructure cookies from both successful and rejected upgrades. Keep configured cookies scoped to their factory and exclude account and session cookies from the shared store. - Apply HTTPS cookie scope to `wss` requests, preserving host and path restrictions and excluding insecure `ws` requests and non-ChatGPT hosts. ## Testing Add HTTP/WebSocket cookie-sharing coverage and local TLS handshake tests for routing-cookie reuse across connectors, rejected-upgrade refreshes, explicit header precedence, cookie scope, session-cookie exclusion, and deletion. GitOrigin-RevId: 6bd6afe16e97cf9758ca7ba207a4e88c969497a4
copyberry
Bot
force-pushed
the
copyberry/codex-internal-to-codex-oss/6bd6afe16e97cf9758ca7ba207a4e88c969497a4
branch
from
September 18, 2026 23:17
4ffe8cd to
12acac2
Compare
copyberry
Bot
deleted the
copyberry/codex-internal-to-codex-oss/6bd6afe16e97cf9758ca7ba207a4e88c969497a4
branch
September 18, 2026 23:17
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Share ChatGPT cookies between HTTP and WebSocket transports
Why
WebSocket handshakes did not reuse the HTTP cookie store or retain response cookies, so routing cookies such as
__oailbwere unavailable to subsequent connections.What changed
Cookieheaders and marking generated headers sensitive.wssrequests, preserving host and path restrictions and excluding insecurewsrequests and non-ChatGPT hosts.Testing
Add HTTP/WebSocket cookie-sharing coverage and local TLS handshake tests for routing-cookie reuse across connectors, rejected-upgrade refreshes, explicit header precedence, cookie scope, session-cookie exclusion, and deletion.