Skip to content

feat(auth): integrate X.509 SDK clients - #936

Merged
jbeckwith-oai merged 5 commits into
codex/x509-java-03-exchange-contractfrom
codex/x509-java-04-client-integration
Aug 26, 2026
Merged

feat(auth): integrate X.509 SDK clients#936
jbeckwith-oai merged 5 commits into
codex/x509-java-03-exchange-contractfrom
codex/x509-java-04-client-integration

Conversation

@jbeckwith-oai

Copy link
Copy Markdown
Contributor

Summary

  • add public sync and async x509Builder entry points backed only by caller-attested X509Transport
  • bind isolated exchange and API clients while preserving exact ownership and close behavior
  • enforce fixed X.509 issuer/API origins, bearer-only route eligibility, and exclusive authentication/provider configuration
  • validate the final request boundary before exchanging or dispatching credentials
  • use OkHttp call lifecycle events so client close cancels exchange/API calls through response-body completion

Security and ownership boundaries

  • API origin is fixed to https://mtls.api.openai.com/v1; the exchange origin remains https://mtls.auth.openai.com/oauth/token
  • no custom base URL, data residency, Azure/Bedrock/provider auth, proxy, arbitrary transport, or organization/project routing can be combined with X.509 mode
  • user-supplied authorization, API-key, proxy-auth, cookie, host/authority, organization, and project headers are rejected at the final sink
  • the authenticator owns only the exchange client; ClientOptions owns the real API client
  • no token caching, shared retry budget, 401 rotation, or long-lived lifecycle policy in this slice

Validation

  • real loopback CONNECT plus mTLS sync/async Files API coverage verifies SNI, certificate chain, exact exchange body, bearer placement, and header separation
  • focused construction, Java-visibility, exclusivity, cloning, build isolation, cancellation, blocked exchange/API close, stalled response-body close, and retry-after-close tests
  • repository lint: passed
  • repository scripts/build: passed
  • full Gradle test graph through scripts/test: BUILD SUCCESSFUL, including R8 and ProGuard; the wrapper cleanup trap subsequently observed its mock-server PID had already exited
  • Castiron custom-code budget: 1610 of 2000 lines, unchanged, 390 lines headroom
  • two independent review cycles completed and remediated; final Reviewer A and Validator B passes clean
  • mandatory thermo-nuclear quality review completed, remediated, and rerun clean

Stack

  1. test: define X.509 workload identity wire contract #929 — executable raw-wire oracle (merged)
  2. feat(auth): add fixed-alias X.509 transport capability #934 — fixed-alias direct mTLS transport capability
  3. feat(auth): add X.509 workload token exchange #935 — identity metadata and exact token exchange
  4. this PR — minimal sync/async client integration with fixed origins and exclusive auth
  5. planned — lifecycle, cache, single-flight, retry/deadline, 401 rotation, installed-JAR docs, and protected live E2E

Stacked on #935.

@jbeckwith-oai
jbeckwith-oai requested a review from a team as a code owner August 25, 2026 05:41
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 25, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-08-26T00:28:22.604617Z 9a3ac27 New commits
🔒 Security Review Completed 2026-08-26T00:29:04.982810Z 9a3ac27 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions

github-actions Bot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

Castiron custom code

Mixed files: 53 → 63

10 newly customized · 0 customizations removed · 2 existing customizations changed · 0 generated baselines changed

Compared 04e7cf883c709a3ac279fa8a. Generated baselines verified.

File Result Current custom patch
openai-java-core/src/main/kotlin/com/openai/client/OpenAIClientAsyncImpl.kt Newly customized +4 / −4
openai-java-core/src/main/kotlin/com/openai/client/OpenAIClientImpl.kt Newly customized +4 / −4
openai-java-core/src/main/kotlin/com/openai/services/async/ContainerServiceAsyncImpl.kt Newly customized +2 / −1
openai-java-core/src/main/kotlin/com/openai/services/async/ResponseServiceAsyncImpl.kt Existing customization changed +5 / −3
openai-java-core/src/main/kotlin/com/openai/services/async/beta/ResponseServiceAsyncImpl.kt Newly customized +2 / −1
openai-java-core/src/main/kotlin/com/openai/services/async/containers/FileServiceAsyncImpl.kt Newly customized +2 / −1
openai-java-core/src/main/kotlin/com/openai/services/async/realtime/CallServiceAsyncImpl.kt Newly customized +5 / −4
openai-java-core/src/main/kotlin/com/openai/services/blocking/ContainerServiceImpl.kt Newly customized +2 / −1
openai-java-core/src/main/kotlin/com/openai/services/blocking/ResponseServiceImpl.kt Existing customization changed +5 / −3
openai-java-core/src/main/kotlin/com/openai/services/blocking/beta/ResponseServiceImpl.kt Newly customized +2 / −1
openai-java-core/src/main/kotlin/com/openai/services/blocking/containers/FileServiceImpl.kt Newly customized +2 / −1
openai-java-core/src/main/kotlin/com/openai/services/blocking/realtime/CallServiceImpl.kt Newly customized +5 / −4
51 existing customizations unchanged
  • openai-java-core/src/main/kotlin/com/openai/models/audio/AudioResponseFormat.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionMessageFunctionToolCall.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionToolMessageParam.kt
  • openai-java-core/src/main/kotlin/com/openai/models/embeddings/Embedding.kt
  • openai-java-core/src/main/kotlin/com/openai/models/embeddings/EmbeddingCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseFunctionToolCall.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseFunctionWebSearch.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseInputItem.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseTextConfig.kt
  • openai-java-core/src/main/kotlin/com/openai/models/videos/Video.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/BetaServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/BetaServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/ResponseServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/WebhookServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/WebhookServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/audio/TranscriptionServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/chat/ChatCompletionServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/finetuning/checkpoints/PermissionServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/BetaService.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/BetaServiceImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/ResponseService.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/WebhookService.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/WebhookServiceImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/audio/TranscriptionServiceImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/chat/ChatCompletionService.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/finetuning/checkpoints/PermissionServiceImpl.kt
  • openai-java-core/src/test/kotlin/com/openai/models/beta/responses/BetaResponsesServerEventTest.kt
  • openai-java-core/src/test/kotlin/com/openai/models/responses/ResponsesServerEventTest.kt
  • openai-java-core/src/test/kotlin/com/openai/services/async/CompletionServiceAsyncTest.kt
  • openai-java-core/src/test/kotlin/com/openai/services/async/ImageServiceAsyncTest.kt
  • openai-java-core/src/test/kotlin/com/openai/services/async/ResponseServiceAsyncTest.kt
  • openai-java-core/src/test/kotlin/com/openai/services/async/WebhookServiceAsyncTest.kt
  • openai-java-core/src/test/kotlin/com/openai/services/async/audio/TranscriptionServiceAsyncTest.kt
  • openai-java-core/src/test/kotlin/com/openai/services/async/beta/ResponseServiceAsyncTest.kt
  • openai-java-core/src/test/kotlin/com/openai/services/async/beta/ThreadServiceAsyncTest.kt
  • openai-java-core/src/test/kotlin/com/openai/services/async/beta/threads/RunServiceAsyncTest.kt
  • openai-java-core/src/test/kotlin/com/openai/services/async/chat/ChatCompletionServiceAsyncTest.kt
  • openai-java-core/src/test/kotlin/com/openai/services/blocking/CompletionServiceTest.kt

11 more in the full report.

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 32915061907 --repo openai/openai-java \
  --name castiron-custom-code-32915061907-1 --dir /tmp/castiron-custom-code-32915061907-1
git apply --stat /tmp/castiron-custom-code-32915061907-1/custom-code.patch
cat /tmp/castiron-custom-code-32915061907-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin 04e7cf883c700e75ab72a34fcaf701bcf7b441c1 9a3ac279fa8a56edc9df884f923c777707c105c7
python3 scripts/castiron/custom_code_report.py report \
  --base 04e7cf883c700e75ab72a34fcaf701bcf7b441c1 \
  --head 9a3ac279fa8a56edc9df884f923c777707c105c7 --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-9a3ac279fa8a
cat /tmp/castiron-custom-code-9a3ac279fa8a/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9603588c79

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@HAYDEN-OAI HAYDEN-OAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the stacked client integration, provider isolation, fixed-origin transport, request headers, lifecycle, and sync/async dispatch. In addition to the existing unresolved cancellation and builder findings, the token-exchange leg currently bypasses the caller’s effective request timeout.

@jbeckwith-oai
jbeckwith-oai force-pushed the codex/x509-java-04-client-integration branch from 9603588 to 90412a6 Compare August 25, 2026 23:10
@jbeckwith-oai
jbeckwith-oai force-pushed the codex/x509-java-03-exchange-contract branch from 51351c5 to 04e7cf8 Compare August 26, 2026 00:25
@jbeckwith-oai
jbeckwith-oai force-pushed the codex/x509-java-04-client-integration branch from 90412a6 to 9a3ac27 Compare August 26, 2026 00:25
@jbeckwith-oai
jbeckwith-oai merged commit 57b2130 into codex/x509-java-03-exchange-contract Aug 26, 2026
3 checks passed
jbeckwith-oai added a commit that referenced this pull request Aug 26, 2026
## Summary

- introduce a single retry/authentication orchestrator for X.509
requests while preserving the ordinary-client retry path unchanged
- cache exchanged bearer tokens with expiry skew, single-flight refresh,
rejected-generation invalidation, and one bounded 401 replay
- propagate request deadlines, cancellation, stream close, and client
close through authentication, backoff, transport calls, request bodies,
responses, parsing, and logging
- preserve exact client/pipeline ownership across sync/async views,
reusable builders, generated `Unit` endpoints, and raw-response
continuations
- add installed-JAR documentation, a runnable example/runtime probe, and
a protected opt-in live X.509 smoke workflow

## Compatibility and security boundaries

- ordinary non-X.509 construction and retry/completion behavior remains
on the pre-existing code path
- X.509 remains fixed to the attested transport and fixed auth/API
origins introduced by the earlier stack layers
- credentials remain bearer-only at the API boundary and are never added
to logs, fixtures, examples, or default test output
- cleanup helpers act only on internal pipeline-owned markers; ordinary
raw-response ownership remains unchanged
- public/source compatibility was verified against both baseline and
proposed API manifests

## Validation

- focused sync/async X.509 lifecycle matrix: passed, including token
races, cancellation, deadlines, retries, 401 replay, builder/view
ownership, request/response cleanup, logging, parsing, streams, and
ordinary-client regressions
- repository lint: passed
- full `scripts/test` graph with Steady: passed, including R8 and
ProGuard artifacts
- Java 21 runtime compatibility probe: passed for core, OkHttp, Bedrock,
and runtime providers
- API/source breaking-change detector: passed for baseline and proposed
public APIs
- staged secret-pattern scan and `git diff --check`: passed
- Castiron custom-code budget: 1668 of 2000 lines, 332 lines headroom;
ratchet unchanged
- first review cycle: two independent agents clean after all findings
were fixed; mandatory thermo-nuclear review clean
- second clean-room review cycle: two fresh independent agents clean on
the exact frozen 49-file diff
(`1e5bba26e91a638915bfa509e87adee10b598c5d92bd23ae54a98a504a4e9fe6`)

## Stack

1. #929 — executable raw-wire oracle (merged)
2. #934 — fixed-alias direct mTLS transport capability
3. #935 — identity metadata and exact token exchange
4. #936 — minimal sync/async client integration with fixed origins and
exclusive auth
5. this PR — lifecycle, cache/single-flight, 401 rotation,
deadline/cancellation ownership, installed-JAR docs, and protected live
E2E

Stacked on #936.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants