Skip to content

fix(web-server): treat a blank chat session id as missing - #795

Merged
justintime4tea merged 1 commit into
nightlyfrom
justingross/fix-blank-chat-session-id
Oct 9, 2026
Merged

justintime4tea merged 1 commit into
nightlyfrom
justingross/fix-blank-chat-session-id

Conversation

@justintime4tea

@justintime4tea justintime4tea commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

A blank chat session id in the request metadata or either session header was taken as given, so every client sending one shared a session and its recorded skill invocations, and orchestration persistence refused it outright. A blank value now falls through to the next source, and a request with no non-blank id gets a fresh one.

Verification

  • cargo +nightly fmt --check, cargo clippy --workspace --all-targets --all-features -- -D warnings, and cargo test --workspace (2,547 passed) on nightly at 513f1ec1.

Fixes: GH-799

@greptile-apps

greptile-apps Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Medium impact] The PR appears safe to merge.

Summary

Blank chat session IDs now fall through from metadata to either session header. Requests without a nonblank ID receive a fresh ID.

  • Nonblank IDs keep their existing priority and value.
  • Tests cover priority, blank fallback, and fresh IDs.
  • The repeated test comments from the previous unnumbered finding are removed.

Reviews (3) · Last reviewed commit: "fix(web-server): treat a blank chat sess..." · Reviewed by Greptile

Comment thread crates/aura-web-server/src/handlers.rs Outdated
@justintime4tea
justintime4tea force-pushed the justingross/fix-blank-chat-session-id branch from 67bfcc3 to 03337ac Compare October 9, 2026 00:48
@justintime4tea
justintime4tea marked this pull request as ready for review October 9, 2026 00:50
@justintime4tea
justintime4tea requested a review from a team October 9, 2026 00:50
A client that sent an empty chat session id, in its metadata or either
session header, had it taken as given. Every such client then shared
one session, and with it each other's recorded skill invocations, since
the skill store keys a session by its string; orchestration persistence
refused the empty id outright and failed the request.

A blank value now counts as none given and falls through to the next
source, and a request with no non-blank id gets a fresh one, as a
request that names no session does.

Fixes: GH-799
@justintime4tea
justintime4tea merged commit fa3861d into nightly Oct 9, 2026
13 checks passed
@justintime4tea
justintime4tea deleted the justingross/fix-blank-chat-session-id branch October 9, 2026 14:17
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 9, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants