Skip to content
This repository was archived by the owner on Sep 7, 2026. It is now read-only.

refactor(client): remove dead endpoint clients (security, unset-provider-tokens, generate_title) - #224

Merged
VascoSch92 merged 1 commit into
mainfrom
vasco/remove-dead-client-endpoints
Jun 23, 2026
Merged

VascoSch92 merged 1 commit into
mainfrom
vasco/remove-dead-client-endpoints

Conversation

@VascoSch92

Copy link
Copy Markdown
Member

What

Removes client surfaces for endpoints that no consumer reaches — they are absent from the agent-server on every branch and unused by agent-canvas. Follow-up to the endpoint-audit.

Removed from client Endpoint(s) Why
SecurityClient (whole class) + ConversationManager.security GET/POST /api/security/policy, GET/POST /api/security/settings, GET /api/security/export-trace Legacy OpenHands monolith endpoints (Invariant analyzer). Served by the old backend, consumed only by the legacy frontend via its own client — never the agent-server (no /api/security/* route on any branch).
SessionClient.unsetProviderTokens POST /api/unset-provider-tokens Legacy-monolith endpoint, absent from the agent-server. SessionClient.acceptTos (/api/accept_tos) is retained.
RemoteConversation.generateTitle POST /api/conversations/{id}/generate_title Dropped server-side (added in agent-server #3100, removed in #3326). Only the internal Conversation.generate_title capability remains, for server-side auto-titling.

Also drops the now-orphaned exports/types: SecuritySettings, SecurityTraceResponse, SecurityClientOptions, GenerateTitleRequest, GenerateTitleResponse.

Scope notes

  • SessionClient is kept — only unsetProviderTokens is removed; acceptTos stays.
  • LocalConversation.generateTitle is kept — it generates a title from message history via the local LLM (no endpoint), so it's unrelated to the dropped server route. generateTitle is removed from the IConversation interface and from RemoteConversation (hence the Conversation class), making it a local-only capability.
  • The security analyzer (SecurityAnalyzer, createSecurityAnalyzer, SetSecurityAnalyzerRequest) is a separate runtime feature and is untouched.
  • No endpoint-audit.config.json change needed — the current config classifies gated calls dynamically against the live agent-server/cloud specs; there are no baseline entries for these to remove.

Breaking change

Removes the public SecurityClient, ConversationManager.security, SessionClient.unsetProviderTokens, generateTitle (from IConversation / RemoteConversation / Conversation), and the types SecuritySettings / SecurityTraceResponse / SecurityClientOptions / GenerateTitleRequest / GenerateTitleResponse.

Verification

  • tsc --noEmit: clean
  • npm run lint: 0 errors (pre-existing no-explicit-any warnings only, in untouched files)
  • npm test: 254/254 pass (14 suites)
  • The endpoint-audit gate runs in CI (it needs a live agent-server, so it isn't run locally)

Base branch

Stacked on vasco/endpoint-audit to keep the diff focused on just these deletions. Happy to retarget to main if preferred.

@github-actions

Copy link
Copy Markdown
Contributor

Endpoint audit

❌ 12 off-contract call(s) — not on the agent-server · classifiers: cloud

Category Count
❌ Off-contract (not on agent-server) 12
  ⛔ no known backend 7
  ↗️ served by cloud 5
➕ Missing API (agent-server has, client lacks) 12
agent-server endpoints 104
client endpoints 102

❌ Not on agent-server (gated, 12)

⛔ (no known backend) — served by no backend we can see (7)

  • DELETE /api/meta-profiles/{}
  • GET /api/meta-profiles
  • GET /api/meta-profiles/{}
  • POST /api/cloud-proxy
  • POST /api/meta-profiles/{}
  • POST /api/meta-profiles/{}/activate
  • POST /api/skills/installed/{}/update

↗️ served by cloud (5)

  • DELETE /api/keys/{}
  • GET /api/keys
  • GET /api/shared-events/search
  • POST /api/accept_tos
  • POST /api/keys

➕ Missing API — agent-server exposes it, client does not implement (12)

  • GET /
  • GET /api/bash/bash_events
  • GET /api/conversations
  • GET /api/conversations/{}/events
  • GET /api/conversations/{}/workspace
  • GET /api/conversations/{}/workspace/{}
  • GET /api/init
  • POST /api/conversations/{}/goal
  • POST /api/conversations/{}/goal/resume
  • POST /api/conversations/{}/goal/stop
  • POST /api/init
  • POST /api/skills/installed/{}/refresh

@VascoSch92
VascoSch92 changed the base branch from vasco/endpoint-audit to main June 23, 2026 12:54
…der-tokens, generate_title)

These client surfaces call endpoints that no consumer reaches: they are
absent from the agent-server (on every branch) and unused by agent-canvas.

- Remove SecurityClient and ConversationManager.security
  (GET/POST /api/security/policy, GET/POST /api/security/settings,
  GET /api/security/export-trace). These are legacy OpenHands monolith
  endpoints (the Invariant analyzer), served by the old backend and
  consumed only by the legacy frontend via its own client — never the
  agent-server, which exposes no /api/security/* route.

- Remove SessionClient.unsetProviderTokens (POST /api/unset-provider-tokens),
  another legacy-monolith endpoint absent from the agent-server.
  SessionClient.acceptTos (/api/accept_tos) is retained.

- Remove RemoteConversation.generateTitle
  (POST /api/conversations/{id}/generate_title). The agent-server dropped
  this route (#3100 added it, #3326 removed it); only the internal
  Conversation.generate_title capability remains for server-side
  auto-titling. LocalConversation.generateTitle (local LLM, no endpoint)
  is retained.

Also drops the now-orphaned exports/types: SecuritySettings,
SecurityTraceResponse, SecurityClientOptions, GenerateTitleRequest,
GenerateTitleResponse.

BREAKING CHANGE: removes the public SecurityClient class,
ConversationManager.security, SessionClient.unsetProviderTokens, and
generateTitle from the IConversation interface / RemoteConversation
(and the Conversation class).
@VascoSch92
VascoSch92 force-pushed the vasco/remove-dead-client-endpoints branch from ed4957f to 2db660f Compare June 23, 2026 13:01
@VascoSch92
VascoSch92 merged commit 23a64f5 into main Jun 23, 2026
7 checks passed
@VascoSch92 VascoSch92 added the type: refactor Code refactoring label Jun 24, 2026
@openhands-release-bot openhands-release-bot Bot added the released: v1.27.0 Shipped in v1.27.0 label Jun 25, 2026
@openhands-release-bot

Copy link
Copy Markdown
Contributor

🚀 Released in v1.27.0.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

released: v1.27.0 Shipped in v1.27.0 type: refactor Code refactoring

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants