Skip to content

fix: restrict proxy authentication to proxy challenges - #1038

Open
dpiet-oai wants to merge 1 commit into
mainfrom
castiron/promotions/pr-91
Open

dpiet-oai wants to merge 1 commit into
mainfrom
castiron/promotions/pr-91

Conversation

@dpiet-oai

Copy link
Copy Markdown
Contributor

Proxy credentials could be attached to an HTTPS origin response posing as a proxy challenge, including a CONNECT request sent inside an established TLS tunnel. Require an HTTP proxy route and reject TLS-origin responses while preserving HTTP proxy and tunnel authentication.

Validation: five proxy-authenticator boundary cases pass, including the TLS CONNECT regression, plus Kotlin formatting and lint. Tests use synthetic authenticator responses; they do not establish a live proxy tunnel.

Castiron-Internal-PR: openai/openai-java-internal#91
Castiron-Source-SHA: d46de9fe1b206fffacca70127ecc634326f732d7
Castiron-Public-Base-SHA: a363812
@dpiet-oai
dpiet-oai marked this pull request as ready for review September 20, 2026 02:21
@dpiet-oai
dpiet-oai requested a review from a team as a code owner September 20, 2026 02:21
@github-actions

github-actions Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

Castiron custom code

✅ No new custom-code files detected.

83 mixed files remain; 0 existing customizations changed.

Compared a3638122166010fcc9e5724b. Generated baselines verified.

83 existing customizations unchanged
  • openai-java-core/src/main/kotlin/com/openai/models/audio/AudioResponseFormat.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/agents/vaults/credentials/CredentialAuth.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/agents/vaults/credentials/CredentialAuthCreateParam.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/agents/vaults/credentials/CredentialAuthRotateParam.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/responses/BetaResponseStreamEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/responses/BetaResponsesServerEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionMessageFunctionToolCall.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionToolMessageParam.kt
  • openai-java-core/src/main/kotlin/com/openai/models/embeddings/Embedding.kt
  • openai-java-core/src/main/kotlin/com/openai/models/embeddings/EmbeddingCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseFunctionToolCall.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseFunctionWebSearch.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseInputItem.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseStreamEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseTextConfig.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponsesServerEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/videos/Video.kt
  • openai-java-core/src/main/kotlin/com/openai/models/webhooks/UnwrapWebhookEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/webhooks/WebhookEndpointWithSecret.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/BetaServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/BetaServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/ResponseServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/ResponseServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/WebhookServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/WebhookServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/audio/TranscriptionServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/beta/agents/SessionServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/beta/agents/SessionServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/chat/ChatCompletionServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/finetuning/checkpoints/PermissionServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/BetaService.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/BetaServiceImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/ResponseService.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/ResponseServiceImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/WebhookService.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/WebhookServiceImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/audio/TranscriptionServiceImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/beta/agents/SessionService.kt

43 more in the full report.

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 35483794037 --repo openai/openai-java \
  --name castiron-custom-code-35483794037-1 --dir /tmp/castiron-custom-code-35483794037-1
git apply --stat /tmp/castiron-custom-code-35483794037-1/custom-code.patch
cat /tmp/castiron-custom-code-35483794037-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin a363812216605acd7ee60a1f5ca986e4905e0195 10fcc9e5724b8e0712b2b63745c121b0b8987f95
python3 scripts/castiron/custom_code_report.py report \
  --base a363812216605acd7ee60a1f5ca986e4905e0195 \
  --head 10fcc9e5724b8e0712b2b63745c121b0b8987f95 --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-10fcc9e5724b
cat /tmp/castiron-custom-code-10fcc9e5724b/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 20, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-09-20T02:23:31.998217Z 10fcc9e Draft marked ready
🔒 Security Review Completed 2026-09-20T02:24:16.463258Z 10fcc9e Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@openai-sdks

openai-sdks Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

OkTest Summary

236/236 SDK tests passed in 17.879s for Java SDK PR #1038.

Test results — 42 files
Test Result Time
tests/chat-completions-complex-body.test.ts ✅ Passed 325ms
tests/chat-completions-create.test.ts ✅ Passed 939ms
tests/chat-completions-stream.test.ts ✅ Passed 659ms
tests/files-content-binary.test.ts ✅ Passed 244ms
tests/files-create-multipart.test.ts ✅ Passed 386ms
tests/files-list-pagination.test.ts ✅ Passed 339ms
tests/initialize-config.test.ts ✅ Passed 273ms
tests/instance-isolation.test.ts ✅ Passed 205ms
tests/models-list.test.ts ✅ Passed 249ms
tests/responses-background-lifecycle.test.ts ✅ Passed 323ms
tests/responses-body-method-errors.test.ts ✅ Passed 463ms
tests/responses-cancel-timeout.test.ts ✅ Passed 231ms
tests/responses-cancel.test.ts ✅ Passed 330ms
tests/responses-compact-retries.test.ts ✅ Passed 416ms
tests/responses-compact.test.ts ✅ Passed 426ms
tests/responses-create-advanced-stream.test.ts ✅ Passed 334ms
tests/responses-create-advanced.test.ts ✅ Passed 1.411s
tests/responses-create-disconnect.test.ts ✅ Passed 1.141s
tests/responses-create-errors.test.ts ✅ Passed 398ms
tests/responses-create-malformed-api-responses.test.ts ✅ Passed 308ms
tests/responses-create-retries.test.ts ✅ Passed 412ms
tests/responses-create-stream-failures.test.ts ✅ Passed 1.575s
tests/responses-create-stream-timeout.test.ts ✅ Passed 240ms
tests/responses-create-stream-wire.test.ts ✅ Passed 6.589s
tests/responses-create-stream.test.ts ✅ Passed 87ms
tests/responses-create-terminal-states.test.ts ✅ Passed 587ms
tests/responses-create-timeout.test.ts ✅ Passed 225ms
tests/responses-create.test.ts ✅ Passed 263ms
tests/responses-delete.test.ts ✅ Passed 262ms
tests/responses-input-items-errors.test.ts ✅ Passed 270ms
tests/responses-input-items-list.test.ts ✅ Passed 278ms
tests/responses-input-items-options.test.ts ✅ Passed 435ms
tests/responses-input-tokens-count-timeout.test.ts ✅ Passed 272ms
tests/responses-input-tokens-count.test.ts ✅ Passed 420ms
tests/responses-malformed-inputs.test.ts ✅ Passed 5.438s
tests/responses-not-found-errors.test.ts ✅ Passed 422ms
tests/responses-parse.test.ts ✅ Passed 671ms
tests/responses-retrieve-retries.test.ts ✅ Passed 339ms
tests/responses-retrieve.test.ts ✅ Passed 373ms
tests/responses-stored-method-errors.test.ts ✅ Passed 969ms
tests/retry-behavior.test.ts ✅ Passed 3.535s
tests/sdk-error-shape.test.ts ✅ Passed 437ms

View OkTest run #35483777781

SDK merge (60585cc3a7ab) · head (10fcc9e5724b) · base (a36381221660) · OkTest (a0be4375e02d)

@dpiet-oai
dpiet-oai enabled auto-merge September 20, 2026 02:32

@markstuart-oai markstuart-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed all three changed files at 10fcc9e5724b8e0712b2b63745c121b0b8987f95. No blocking correctness or structural findings. The guard belongs in the OkHttp adapter: it uses the selected proxy and transport handshake to reject TLS-origin 407s, including application CONNECT requests, while retaining HTTP-proxy and pre-TLS CONNECT authentication.

I checked those distinctions against the pinned OkHttp 4.12.0 implementation and verified successful CI, including the OkHttp module's test task. The five new tests exercise synthetic authenticator responses; this review did not run a live proxy/TLS exchange.

@dpiet-oai
dpiet-oai added this pull request to the merge queue Sep 20, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Sep 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants