This repository was archived by the owner on Sep 7, 2026. It is now read-only.
Repository navigation
refactor(client): remove dead endpoint clients (security, unset-provider-tokens, generate_title) - #224
Merged
Conversation
Contributor
Endpoint audit❌ 12 off-contract call(s) — not on the agent-server · classifiers: cloud
❌ Not on agent-server (gated, 12)⛔ (no known backend) — served by no backend we can see (7)
|
…der-tokens, generate_title)
These client surfaces call endpoints that no consumer reaches: they are
absent from the agent-server (on every branch) and unused by agent-canvas.
- Remove SecurityClient and ConversationManager.security
(GET/POST /api/security/policy, GET/POST /api/security/settings,
GET /api/security/export-trace). These are legacy OpenHands monolith
endpoints (the Invariant analyzer), served by the old backend and
consumed only by the legacy frontend via its own client — never the
agent-server, which exposes no /api/security/* route.
- Remove SessionClient.unsetProviderTokens (POST /api/unset-provider-tokens),
another legacy-monolith endpoint absent from the agent-server.
SessionClient.acceptTos (/api/accept_tos) is retained.
- Remove RemoteConversation.generateTitle
(POST /api/conversations/{id}/generate_title). The agent-server dropped
this route (#3100 added it, #3326 removed it); only the internal
Conversation.generate_title capability remains for server-side
auto-titling. LocalConversation.generateTitle (local LLM, no endpoint)
is retained.
Also drops the now-orphaned exports/types: SecuritySettings,
SecurityTraceResponse, SecurityClientOptions, GenerateTitleRequest,
GenerateTitleResponse.
BREAKING CHANGE: removes the public SecurityClient class,
ConversationManager.security, SessionClient.unsetProviderTokens, and
generateTitle from the IConversation interface / RemoteConversation
(and the Conversation class).
VascoSch92
force-pushed
the
vasco/remove-dead-client-endpoints
branch
from
June 23, 2026 13:01
ed4957f to
2db660f
Compare
enyst
approved these changes
Jun 23, 2026
This was referenced Jun 23, 2026
Contributor
|
🚀 Released in v1.27.0. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Removes client surfaces for endpoints that no consumer reaches — they are absent from the agent-server on every branch and unused by agent-canvas. Follow-up to the endpoint-audit.
SecurityClient(whole class) +ConversationManager.securityGET/POST /api/security/policy,GET/POST /api/security/settings,GET /api/security/export-trace/api/security/*route on any branch).SessionClient.unsetProviderTokensPOST /api/unset-provider-tokensSessionClient.acceptTos(/api/accept_tos) is retained.RemoteConversation.generateTitlePOST /api/conversations/{id}/generate_titleConversation.generate_titlecapability remains, for server-side auto-titling.Also drops the now-orphaned exports/types:
SecuritySettings,SecurityTraceResponse,SecurityClientOptions,GenerateTitleRequest,GenerateTitleResponse.Scope notes
SessionClientis kept — onlyunsetProviderTokensis removed;acceptTosstays.LocalConversation.generateTitleis kept — it generates a title from message history via the local LLM (no endpoint), so it's unrelated to the dropped server route.generateTitleis removed from theIConversationinterface and fromRemoteConversation(hence theConversationclass), making it a local-only capability.SecurityAnalyzer,createSecurityAnalyzer,SetSecurityAnalyzerRequest) is a separate runtime feature and is untouched.endpoint-audit.config.jsonchange needed — the current config classifies gated calls dynamically against the live agent-server/cloud specs; there are no baseline entries for these to remove.Breaking change
Removes the public
SecurityClient,ConversationManager.security,SessionClient.unsetProviderTokens,generateTitle(fromIConversation/RemoteConversation/Conversation), and the typesSecuritySettings/SecurityTraceResponse/SecurityClientOptions/GenerateTitleRequest/GenerateTitleResponse.Verification
tsc --noEmit: cleannpm run lint: 0 errors (pre-existingno-explicit-anywarnings only, in untouched files)npm test: 254/254 pass (14 suites)Base branch
Stacked on
vasco/endpoint-auditto keep the diff focused on just these deletions. Happy to retarget tomainif preferred.