| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
The separator-collision test does not exercise the stated collision, and new guards diverge from the repository’s required validation convention.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overviewScopes OpenAI response, conversation, and index storage by caller isolation keys while retaining shared behavior when isolation is unconfigured.
Changes:
| File | Description |
|---|---|
| OpenAIResponsesIsolationTests.cs | Tests response ownership isolation. |
| OpenAIConversationsIsolationTests.cs | Tests conversation and index isolation. |
| ServiceCollectionExtensions.cs | Injects isolation into response storage. |
| InMemoryResponsesService.cs | Scopes response and conversation storage IDs. |
| IsolationKeyResolver.cs | Composes escaped scoped identifiers. |
| EndpointRouteBuilderExtensions.Responses.cs | Applies isolation to agent-specific responses. |
| EndpointRouteBuilderExtensions.Conversations.cs | Wraps conversation storage and indexing. |
| IsolationKeyScopedConversationStorage.cs | Adds scoped conversation storage decorator. |
| IsolationKeyScopedAgentConversationIndex.cs | Adds scoped conversation-index decorator. |
| AgentWebChat.AgentHost/Program.cs | Expands production isolation guidance. |
| af-hosting/README.md | Documents multi-user isolation requirements. |
dotnet/src/Microsoft.Agents.AI.Hosting.OpenAI/Conversations/IsolationKeyScopedConversationStorage.cs:62
ArgumentNullException.ThrowIfNull(conversation);
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
Sorry, something went wrong.
There was a problem hiding this comment.
Result: Findings reported
Scope: full PR (1 commit(s)): c68716c27714
Model: gpt-5.6-sol-fast
The PR consistently scopes conversation, conversation-index, and response storage keys while preserving bare wire identifiers; strict missing-key behavior and broad cross-caller tests provide strong guardrails. Two residual issues remain: resolver construction assumes a singleton isolation provider despite the public custom-provider contract, and index scoping multiplies a fixed global cache by the number of callers. These can prevent endpoint startup for scoped providers and make conversation listings incomplete beyond 1,000 active caller-agent partitions.
Reviewed the supplied pull-request change set across correctness, security/reliability, architecture, and failure behavior.
2 verified findings remained after source verification (2 medium) across 2 files. Details are attached to the affected lines below.
Affected areas: dotnet/src/Microsoft.Agents.AI.Hosting.OpenAI/Conversations/IsolationKeyScopedAgentConversationIndex.cs, dotnet/src/Microsoft.Agents.AI.Hosting.OpenAI/ServiceCollectionExtensions.cs
Sorry, something went wrong.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
| Back | FazBrowse Home | New Git URL |
Motivation & Context
Align OpenAI-compatible hosting storage with the existing AgentIsolationKeyProvider behavior used by other hosting surfaces. This keeps caller-scoped state handling consistent when applications opt into agent isolation while preserving current behavior for applications without a provider.
Description & Review Guide
Related Issue
Related to #3000.
Contribution Checklist