Repository navigation
fix(client): load earlier turns works for MCP threads over T3 Connect - #17599
Merged
Merged
Conversation
MCP-created thread ids contain ":", which the HttpApi client percent-encodes in the request path. The DPoP proof signed the raw id, so the environment rejected thread history, snapshot, and bounded snapshot requests for those threads with a URL mismatch, surfaced as invalid_credential. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
juliusmarminge
enabled auto-merge (squash)
October 9, 2026 20:25
Contributor
ApprovabilityVerdict: Approved at Macroscope's review found this PR approvable — This is a focused client bug fix that aligns DPoP-signed URLs with the percent-encoded URLs actually sent for MCP thread IDs. It touches only three existing request paths and adds targeted regression coverage for all of them. You can add or adjust custom eligibility rules. Learn more. |
Contributor
Thread transfer impact✅ Thread transfer remains within every enforced ceiling.
Baseline: Scenario and decoded snapshot size10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.
Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed. |
github-actions Bot
added a commit
to omarcresp/t3code-flake
that referenced
this pull request
Oct 10, 2026
## What's Changed * chore(deps): upgrade Effect to 4.0.2 by @juliusmarminge in pingdotgg/t3code#17571 * fix(devices): recover stalled video without losing simulator input by @juliusmarminge in pingdotgg/t3code#17566 * fix(web): keep checkout stable while pr actions load by @maria-rcks in pingdotgg/t3code#16625 * fix(mobile): show waiting thread status by @maria-rcks in pingdotgg/t3code#16693 * feat(web): add parent thread breadcrumb navigation by @maria-rcks in pingdotgg/t3code#16666 * fix(server): restart inactivity after snoozed threads wake by @maria-rcks in pingdotgg/t3code#16674 * feat(desktop): passkeys in the in-app browser on macOS by @juliusmarminge in pingdotgg/t3code#16952 * fix(client): load earlier turns works for MCP threads over T3 Connect by @juliusmarminge in pingdotgg/t3code#17599 * refactor(client): sign relay request URLs built from the HttpApi contract by @juliusmarminge in pingdotgg/t3code#17602 * refactor(source-control): add @t3tools/source-control-core by @juliusmarminge in pingdotgg/t3code#17573 * refactor(source-control): Forgejo lives in @t3tools/source-control-forgejo by @juliusmarminge in pingdotgg/t3code#17581 * refactor(source-control): Azure DevOps lives in @t3tools/source-control-azure-devops by @juliusmarminge in pingdotgg/t3code#17592 * refactor(source-control): GitLab lives in @t3tools/source-control-gitlab by @juliusmarminge in pingdotgg/t3code#17594 * refactor(source-control): Bitbucket lives in @t3tools/source-control-bitbucket by @juliusmarminge in pingdotgg/t3code#17597 * refactor(source-control): GitHub lives in @t3tools/source-control-github by @juliusmarminge in pingdotgg/t3code#17607 * refactor(usage): transcript readers come from their drivers by @juliusmarminge in pingdotgg/t3code#17576 * refactor(usage): OpenCode usage comes from provider-opencode by @juliusmarminge in pingdotgg/t3code#17577 * refactor(usage): Cursor account usage comes from provider-cursor by @juliusmarminge in pingdotgg/t3code#17578 * refactor(usage): Antigravity usage is a reader on its driver by @juliusmarminge in pingdotgg/t3code#17579 * refactor(usage): usage readers use Effect FileSystem and SqlClient by @juliusmarminge in pingdotgg/t3code#17615 * fix(web): composer context strip pads both edges evenly by @limineol in pingdotgg/t3code#17562 * test(usage): v4 cache upgrade test waits for the migrated cache write by @Mnigos in pingdotgg/t3code#17553 * feat(mobile): support Duo in the shared iOS app by @juliusmarminge in pingdotgg/t3code#12648 * refactor(source-control): GitManager reads provider resolvers, not host kinds by @juliusmarminge in pingdotgg/t3code#17617 * refactor(source-control): PullRequestService reads GitHub resolvers, not its kind by @juliusmarminge in pingdotgg/t3code#17619 * refactor(source-control): Forgejo identity and Azure DevOps addressing move into their packages by @juliusmarminge in pingdotgg/t3code#17624 * refactor: home directory comes from a HostProcessHomeDirectory reference by @juliusmarminge in pingdotgg/t3code#17628 * refactor(shared): host process references live in a HostProcess module by @juliusmarminge in pingdotgg/t3code#17641 * feat(web): filter PR comments by bots and resolved threads by @juliusmarminge in pingdotgg/t3code#17645 * fix(clients): remove redundant prefix from PR watch status by @extoci in pingdotgg/t3code#17635 * fix(web): pending requests wait until you stop typing by @maria-rcks in pingdotgg/t3code#17637 * fix(models): remove new badges from Claude Opus and Sonnet 5.5 by @extoci in pingdotgg/t3code#17646 * fix(ui): keep focus and selection borders visible across the app by @maria-rcks in pingdotgg/t3code#16675 * fix(mobile): prevent row presses during native back swipes by @juliusmarminge in pingdotgg/t3code#17648 * fix(server): Codex shadow homes replace stray sqlite maintenance locks by @juliusmarminge in pingdotgg/t3code#17663 * feat(desktop): T3 Code can be your default web browser on macOS by @juliusmarminge in pingdotgg/t3code#17587 * test(server): the ACP process-tree test no longer collides with the runner's own pid by @yordis in pingdotgg/t3code#17647 * fix(web): keep branch restore action inline in narrow composers by @Saikrishna1876 in pingdotgg/t3code#14811 * fix(web): composer banner actions stay inline whenever they fit by @maria-rcks in pingdotgg/t3code#17640 **Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261009.2886...v0.0.46-nightly.20261010.2908 Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261010.2908
github-actions Bot
added a commit
to davidvanderklay/t3code-flake
that referenced
this pull request
Oct 10, 2026
## What's Changed * chore(deps): upgrade Effect to 4.0.2 by @juliusmarminge in pingdotgg/t3code#17571 * fix(devices): recover stalled video without losing simulator input by @juliusmarminge in pingdotgg/t3code#17566 * fix(web): keep checkout stable while pr actions load by @maria-rcks in pingdotgg/t3code#16625 * fix(mobile): show waiting thread status by @maria-rcks in pingdotgg/t3code#16693 * feat(web): add parent thread breadcrumb navigation by @maria-rcks in pingdotgg/t3code#16666 * fix(server): restart inactivity after snoozed threads wake by @maria-rcks in pingdotgg/t3code#16674 * feat(desktop): passkeys in the in-app browser on macOS by @juliusmarminge in pingdotgg/t3code#16952 * fix(client): load earlier turns works for MCP threads over T3 Connect by @juliusmarminge in pingdotgg/t3code#17599 * refactor(client): sign relay request URLs built from the HttpApi contract by @juliusmarminge in pingdotgg/t3code#17602 * refactor(source-control): add @t3tools/source-control-core by @juliusmarminge in pingdotgg/t3code#17573 * refactor(source-control): Forgejo lives in @t3tools/source-control-forgejo by @juliusmarminge in pingdotgg/t3code#17581 * refactor(source-control): Azure DevOps lives in @t3tools/source-control-azure-devops by @juliusmarminge in pingdotgg/t3code#17592 * refactor(source-control): GitLab lives in @t3tools/source-control-gitlab by @juliusmarminge in pingdotgg/t3code#17594 * refactor(source-control): Bitbucket lives in @t3tools/source-control-bitbucket by @juliusmarminge in pingdotgg/t3code#17597 * refactor(source-control): GitHub lives in @t3tools/source-control-github by @juliusmarminge in pingdotgg/t3code#17607 * refactor(usage): transcript readers come from their drivers by @juliusmarminge in pingdotgg/t3code#17576 * refactor(usage): OpenCode usage comes from provider-opencode by @juliusmarminge in pingdotgg/t3code#17577 * refactor(usage): Cursor account usage comes from provider-cursor by @juliusmarminge in pingdotgg/t3code#17578 * refactor(usage): Antigravity usage is a reader on its driver by @juliusmarminge in pingdotgg/t3code#17579 * refactor(usage): usage readers use Effect FileSystem and SqlClient by @juliusmarminge in pingdotgg/t3code#17615 * fix(web): composer context strip pads both edges evenly by @limineol in pingdotgg/t3code#17562 * test(usage): v4 cache upgrade test waits for the migrated cache write by @Mnigos in pingdotgg/t3code#17553 * feat(mobile): support Duo in the shared iOS app by @juliusmarminge in pingdotgg/t3code#12648 * refactor(source-control): GitManager reads provider resolvers, not host kinds by @juliusmarminge in pingdotgg/t3code#17617 * refactor(source-control): PullRequestService reads GitHub resolvers, not its kind by @juliusmarminge in pingdotgg/t3code#17619 * refactor(source-control): Forgejo identity and Azure DevOps addressing move into their packages by @juliusmarminge in pingdotgg/t3code#17624 * refactor: home directory comes from a HostProcessHomeDirectory reference by @juliusmarminge in pingdotgg/t3code#17628 * refactor(shared): host process references live in a HostProcess module by @juliusmarminge in pingdotgg/t3code#17641 * feat(web): filter PR comments by bots and resolved threads by @juliusmarminge in pingdotgg/t3code#17645 * fix(clients): remove redundant prefix from PR watch status by @extoci in pingdotgg/t3code#17635 * fix(web): pending requests wait until you stop typing by @maria-rcks in pingdotgg/t3code#17637 * fix(models): remove new badges from Claude Opus and Sonnet 5.5 by @extoci in pingdotgg/t3code#17646 * fix(ui): keep focus and selection borders visible across the app by @maria-rcks in pingdotgg/t3code#16675 * fix(mobile): prevent row presses during native back swipes by @juliusmarminge in pingdotgg/t3code#17648 * fix(server): Codex shadow homes replace stray sqlite maintenance locks by @juliusmarminge in pingdotgg/t3code#17663 * feat(desktop): T3 Code can be your default web browser on macOS by @juliusmarminge in pingdotgg/t3code#17587 * test(server): the ACP process-tree test no longer collides with the runner's own pid by @yordis in pingdotgg/t3code#17647 * fix(web): keep branch restore action inline in narrow composers by @Saikrishna1876 in pingdotgg/t3code#14811 * fix(web): composer banner actions stay inline whenever they fit by @maria-rcks in pingdotgg/t3code#17640 **Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261009.2886...v0.0.46-nightly.20261010.2908 Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261010.2908
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Over T3 Connect, "Load earlier turns" on a thread created through MCP tools (id
mcp:…) failed with "The environment rejected this client's credentials (invalid_credential)." The server log showedenvironment.dpop.failure_code: "url_mismatch".The DPoP proof signed
/api/orchestration/threads/mcp:…/historywith the raw id, while the HttpApi client sent the percent-encoded path/threads/mcp%3A…/history. The environment compares the proof against the URL it received, so it rejected the request. The credential refresh-and-retry signed the same wrong URL, so it failed too. Thread snapshot and bounded snapshot requests built their URLs the same way.The fix encodes the thread id in all three signed URLs. A new test loads each one with an
mcp:id and checks that the signed URL equals the URL actually fetched. Without the fix the test fails.Possible follow-up: the signed URL and the sent URL are still built separately. Signing the request URL the client actually sends would rule out this whole class of bug.
Done by Claude Opus 5.5 in Claude Code (via T3 Code).
🤖 Generated with Claude Code
Fixes #15772