Dashboard › opencode-lore › Gateway Responses privacy, recovery, st…
01a0aeaf-51c5-7774-9407-4b0a089ac7feReplay transformed full history with store:false; never trust client state or previous_response_id. Validate identities, roles, sequencing, usage, limits, terminal reasons, stream mode, and recovery envelopes before accepting output. Accumulate privately and expose only finalized authoritative text; never leak recall data, diagnostics, ciphertext, references, or synthetic lifecycle events. Commit recall and temporal state only after successful EOF and postResponse; otherwise roll back and finalize unsuccessful accounting exactly once with empty output and a fixed public error. Recover nonfatal recall failures when safe principal output exists, using the same strict JSON/SSE executors as normal follow-ups. Cancellation and reader.cancel() must not block cleanup or allow late commits. Synthetic injected deltas must not lead with reasoning.