fix: honour HERMES_CODEX_BASE_URL on the raw Codex client too

The raw_codex branch of _resolve_openai_codex_branch (main agent built without
explicit creds via agent_init._routed_client_kwargs, and the mid-turn fallback
chain) still hardcoded the official Codex endpoint while the pooled/aux/singleton
paths honoured the override, so a proxy user's main agent silently bypassed it.
Hoist the profile-scoped read into _codex_base_url_override and use it in both
builders; the Cloudflare identity headers follow the resolved base_url.

Review finding: raw_codex client ignored HERMES_CODEX_BASE_URL while pooled/aux/singleton honoured it.
This commit is contained in:
teknium1
2026-09-14 21:16:16 -07:00
committed by Teknium
parent 70ff4863d7
commit 9336fb11cd
2 changed files with 26 additions and 5 deletions
+10 -5
View File
@@ -2774,6 +2774,12 @@ def _build_xai_oauth_aux_client(model: str) -> Tuple[Optional[Any], Optional[str
return CodexAuxiliaryClient(real_client, model), model
def _codex_base_url_override() -> str:
"""Profile-scoped ``HERMES_CODEX_BASE_URL`` (same read as the API-key env vars: under a
multiplexer the routed profile's .env decides the endpoint, never a sibling's process env)."""
return _scoped_key_env("HERMES_CODEX_BASE_URL").rstrip("/")
def _build_codex_client(model: str) -> Tuple[Optional[Any], Optional[str]]:
"""CodexAuxiliaryClient for an explicit model; (None, None) without a Codex OAuth token.
@@ -2787,9 +2793,7 @@ def _build_codex_client(model: str) -> Tuple[Optional[Any], Optional[str]]:
return None, None
pool_present, entry = _select_pool_entry("openai-codex")
codex_token = _pool_runtime_api_key(entry) if pool_present else None
# Same profile-scoped read as the API-key env vars: under a multiplexer the routed profile's
# .env decides the endpoint, never a sibling profile's process env.
codex_override = _scoped_key_env("HERMES_CODEX_BASE_URL").rstrip("/")
codex_override = _codex_base_url_override()
if codex_token:
base_url = codex_override or _pool_runtime_base_url(entry, _CODEX_AUX_BASE_URL) or _CODEX_AUX_BASE_URL
else:
@@ -4672,8 +4676,9 @@ def _resolve_openai_codex_branch(req: _ResolveRequest) -> _ResolveResult:
if not codex_token:
logger.warning(no_token_msg)
return None, None
raw_client = _create_openai_client(api_key=codex_token, base_url=_CODEX_AUX_BASE_URL,
default_headers=_codex_cloudflare_headers(codex_token))
base_url = _codex_base_url_override() or _CODEX_AUX_BASE_URL
raw_client = _create_openai_client(api_key=codex_token, base_url=base_url,
default_headers=_codex_cloudflare_headers(codex_token, base_url=base_url))
return raw_client, _normalize_resolved_model(model, req.provider)
client, default = _build_codex_client(model)
return _route_or_warn(req, client, default, no_token_msg)