Overview
@gausszhou/dsh-opencode-session-id
README / EN
Package documentation
Registry summary
dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.
Read the full README on GitHubLIMITATIONS
Known limitations
- The session id comes from `options.sessionId` (agent-loop fills it in per session); without a session context, the fallback chain is `sessionIdEnv` > `DSH_SESSION_ID` (the process's startup session in web deployments) > an in-process random id. - Covers protocols that go through `fetch`, such as `openai-completions` / `openai-responses` / `anthropic-messages`; `transport: websocket` does not use fetch and is out of scope. - The global fetch wrapper only appends request headers when an opencode endpoint is matched — nothing else is changed. The wire token is a one-way SHA-256 hash of the uuid portion of `session-<uuid>` (the `session-` prefix excluded, e.g. `0RpJJnxJ`), so the backend cannot reverse it to the original id; changing `nanoidAlphabet` / `nanoidLength` changes every token, breaking association with old records.
