👓 feat: Read Attached Workspace Files - #15524
Conversation
There was a problem hiding this comment.
🟡 Changes recommended
Path validation in the new workspace client should reject non-canonical segments (e.g., empty or .) to avoid ambiguity between server validation and worker path resolution.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
This PR wires “attached BYOM workspace” file reads into LibreChat’s existing read_file tool by introducing a bounded Code API workspace-tools/execute client, advertising the workspace/ namespace only when an attached environment is selected, and routing read_file calls accordingly.
Changes:
- Added a validated, size-bounded
executeWorkspaceToolclient for Code API workspace reads/search. - Updated agent tool registration to advertise
workspace/{relativePath}+start_line/max_linesonly for attached environments, and preserved upgrade behavior when skills are enabled mid-run. - Routed
read_filecalls withworkspace/…paths to a new attached-workspace handler and added integration plumbing/tests through the legacy/apilayer.
File summaries
| File | Description |
|---|---|
| packages/api/src/code/workspace.ts | New Code API workspace-tools client with request/response validation and response-size bounds. |
| packages/api/src/code/workspace.spec.ts | Unit tests covering auth forwarding, malformed results, and response bounding. |
| packages/api/src/code/index.ts | Exports the new workspace module from the code package barrel. |
| packages/api/src/agents/tools.ts | Adds workspaceTools flag and attached-workspace read_file schema/description. |
| packages/api/src/agents/tools.spec.ts | Verifies attached-workspace read_file advertising and upgrade preservation. |
| packages/api/src/agents/skills.ts | Threads workspaceTools through skill catalog injection/tool registration. |
| packages/api/src/agents/initialize.ts | Enables workspaceTools only when the effective code env is attached. |
| packages/api/src/agents/handlers.ts | Routes workspace/ reads to readWorkspaceFile and supports paginated line numbering. |
| packages/api/src/agents/handlers.spec.ts | Tests routing, pagination behavior, gating to attached env only, and error redaction. |
| api/server/services/Files/Code/process.js | Implements readWorkspaceFile that authenticates and calls executeWorkspaceTool. |
| api/server/services/Files/Code/process.spec.js | Tests that attached-workspace reads forward auth/profile/worker identity correctly. |
| api/server/services/Endpoints/agents/skillDeps.js | Exposes readWorkspaceFile as a stable dependency for agent handlers. |
| api/server/services/Endpoints/agents/skillDeps.spec.js | Confirms the new dependency is surfaced through getSkillToolDeps(). |
Review details
- Files reviewed: 13/13 changed files
- Comments generated: 2
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
3aad3af to
71289be
Compare
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Codex Review: Didn't find any major issues. 👍 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 71289be3fb
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review the latest head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 187d4e1780
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Codex Review: Didn't find any major issues. Another round soon, please! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2684e0310c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Codex Review: Didn't find any major issues. Can't wait for the next one! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
…pace-tool-adapter
Summary
I connected attached BYOM workspace reads to LibreChat’s existing
read_filetool. This PR depends on LibreChat-AI/code-interpreter#90 for the authenticated Code API workspace endpoint.workspace/{relativePath}reads only when the selected code environment is attached./mnt/databehaviors for managed environments.start_lineandmax_linespagination only for attached environments.Change Type
Testing
origin/dev.--noEmitbefore the upstream dependency update; after rebasing, the shared local@librechat/agentsinstall reports pre-existingRuntimeProviderNameerrors in memory tests, so CI will validate against the branch lockfile.workspace/notes.txtread, rejected traversal locally, and rejected an escaping symlink with HTTP 422.Test Configuration:
http://127.0.0.1:23115/v1127.0.0.1:26383.gitmetadataChecklist