Follow-up to #7077 / #7104.
#7104 removed the fallback that dumped the whole raw runtime.context into the App Context note. One un-namespaced path is still open, in _copilotkit_from_runtime_context (sdk-python/copilotkit/copilotkit_lg_middleware.py:285-293 on main):
nested = runtime_context.get("copilotkit")
if CopilotKitMiddleware._has_copilotkit_payload(nested):
return nested
if CopilotKitMiddleware._has_copilotkit_payload(runtime_context): # <- un-namespaced
return runtime_context
_has_copilotkit_payload is true for any dict with a truthy top-level context or actions key. _get_copilotkit_context calls this for runtime.context, and also for the config["context"] and config["configurable"] carriers. _build_app_context_note then serializes .get("context") into the system prompt.
Result: with ag-ui-langgraph>=0.0.42 forwarding config["configurable"] into the runtime context, an app that keeps its own context key in configurable, such as configurable={"context": {...tenant data...}}, still has that value rendered into the model-visible system prompt as App Context:. This is the same kind of leak as #7077, but only for that one key, not the whole dict. A top-level actions key is also picked up as frontend tools.
Expected: only <carrier>["copilotkit"] is read, as #7077 asked.
Suggested fix: drop the un-namespaced branch, and add a regression test for a raw top-level context on runtime.context and on configurable. Before merging, check which callers still rely on it. langgraph_agui_agent.py's subgraph bridge (fee7ec2) should be writing the namespaced key. Confirm that, so subgraph context keeps working.
Originally flagged by CodeRabbit on #7104, outside the diff.
Follow-up to #7077 / #7104.
#7104 removed the fallback that dumped the whole raw
runtime.contextinto the App Context note. One un-namespaced path is still open, in_copilotkit_from_runtime_context(sdk-python/copilotkit/copilotkit_lg_middleware.py:285-293onmain):_has_copilotkit_payloadis true for any dict with a truthy top-levelcontextoractionskey._get_copilotkit_contextcalls this forruntime.context, and also for theconfig["context"]andconfig["configurable"]carriers._build_app_context_notethen serializes.get("context")into the system prompt.Result: with
ag-ui-langgraph>=0.0.42forwardingconfig["configurable"]into the runtime context, an app that keeps its owncontextkey inconfigurable, such asconfigurable={"context": {...tenant data...}}, still has that value rendered into the model-visible system prompt asApp Context:. This is the same kind of leak as #7077, but only for that one key, not the whole dict. A top-levelactionskey is also picked up as frontend tools.Expected: only
<carrier>["copilotkit"]is read, as #7077 asked.Suggested fix: drop the un-namespaced branch, and add a regression test for a raw top-level
contextonruntime.contextand onconfigurable. Before merging, check which callers still rely on it.langgraph_agui_agent.py's subgraph bridge (fee7ec2) should be writing the namespaced key. Confirm that, so subgraph context keeps working.Originally flagged by CodeRabbit on #7104, outside the diff.