Pinning a conversation with a non-OpenAI provider leaks all pinned OpenAI conversations into the list
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 58/100
Research direction
Start by reproducing the issue with a custom provider using a custom base_url and wire_api = "responses". Trace the pin action and the full reload of the pinned list, then verify that the list remains scoped to the active provider and that continuing a conversation does not bypass its provider.
Written by the indexing model from the issue text.
Description
Describe the bug
When Codex is configured with a custom provider (e.g. wire_api = "responses" with a custom base_url), the conversation list is correctly scoped to that provider — OpenAI conversations are not visible.
However, as soon as you pin any conversation while on the custom provider, all conversations that were previously pinned on the OpenAI provider suddenly appear in the pinned list.
Steps to reproduce
- Configure Codex with a non-OpenAI provider (custom
base_url,wire_api = "responses") - Start a new conversation — confirm you only see conversations for that provider
- Pin that conversation using the pin action
- Observe: the pinned list now shows the just-pinned conversation plus all conversations previously pinned on the OpenAI account
Expected behavior
Pinning a conversation should not affect visibility of conversations from other providers. The pinned list should remain scoped to the active provider.
Actual behavior
Pinning triggers a full reload of the pinned list that ignores the active provider filter, causing all OpenAI-provider pinned conversations to bleed into the view.
Additional context
If the user then continues one of the leaked OpenAI conversations, requests are sent to the OpenAI API directly (bypassing the custom base_url), silently charging the personal OpenAI account.
- Dominant language
- Rust
- Stars
- 125k
- Forks
- 19.5k
- Avg merge
- 1m
- Merged PRs (30d)
- 1k
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from openai/codex
-
enhancement remote
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
bug CLI windows-os
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
macOS sandbox blocks hw.optional.arm64 sysctl, causing Flutter to misdetect Apple Silicon as x64 Openbug CLI sandbox
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
bug CLI TUI
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
-
CLI config enhancement skills
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
kwakseongjae/auto-hwp#319 ·
-
area:cli bug filter-quality good first issue priority:medium
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
Difficulty 1/5 Under an hour Newbie friendliness 72/100
bevyengine/bevy#25861 ·
-
comp-datalake
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
ClickHouse/ClickHouse#121222 ·
-
A-linter
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
oxc-project/oxc#26863 ·