Repository navigation
Add a place-axis project parameter to save_memory - #761
Conversation
A project home sends repo_hash as null: the server stores one (scope_kind, scope_id) home and derives the response's repo hash from it, so a hash beside a project is dropped, not kept. A blank project is rejected rather than read as absent, because absent falls back to the repo or org home and would silently widen where the memory surfaces. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
PR Summary by QodoAdd project-scoped placement to save_memory
AI Description
Diagram
High-Level Assessment
Files changed (5)
|
Code Review by Qodo
1.
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cec80020c5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| ["repo_hash"] = global ? null : cwdRepoHash, | ||
| // The place axis: a project home wins over the repo, so the record carries no repo hash. | ||
| ["project"] = project, | ||
| ["repo_hash"] = global || project is not null ? null : cwdRepoHash, |
There was a problem hiding this comment.
Fail closed when the server cannot honor project scope
When project is used against a server predating support for that request field, the server ignores project but still receives repo_hash: null, which it interprets as an org-wide home. A memory requested for one project can therefore surface in every repository—and, for a broad audience, expose its contents across the organization—during staggered client/server upgrades. Gate this path on server capability/version or otherwise require an acknowledgement before removing the repository scope.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Addressed in 21f9fcd: the cwd repo hash now rides along with project. A server that resolves project drops the hash (verified on the server branch: after ResolveSaveScopeAsync only the resolved scope is read), and a server that does not know the field homes the memory at the repo, narrower than asked rather than org-wide. No version gate: the fallback is in the request itself.
One correction to the framing: place does not govern visibility, audience does. A user-audience memory homed at org is still visible only to that user, so the failure mode is surfacing in every repo's index, not exposure across the organization. The remaining gap is a project save from outside a checkout against an old server, which has no narrower fallback than org.
A server without project homes ignores the field and reads repo_hash: null as org-wide, so the hash rides along: a server that resolves project drops it, an older one homes the memory at the repo, narrower than asked rather than wider. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Closes #755 — AI-2473
What & why
save_memorycould only home a memory at the cwd repo or, withglobal: true, at the org, so a learning that spans a project's repos landed at org and was injected into every repo's SessionStart index. The tool now takes an optionalprojectslug on the place axis, the same field and meaning asrescope_memory'sproject, and distinct fromaudience_project(the people axis). A project save skips the "cannot resolve the current repository" check, since the project is the home. Needs the server side of AI-2469 (projectonPOST /api/memories).Where to look
The cwd repo hash still rides along with
project. A server with AI-2469 drops it once the project resolves; a server without it ignoresprojectand would read a null hash as org-wide, so with the hash it homes the memory at the repo, narrower than asked rather than wider. A present-but-blankprojectis rejected locally instead of being read as absent, since absent falls back to the repo or org home.projectbesideglobal: trueis not an error; project wins, matching the server andrescope_memory.Verification