Skip to content

session_store_sql returns deleted sessions forever: no DELETE verb on POST /agents/analytics/query or /agents/sessions/* #4942

Description

@willmarkley

Describe the bug

The session_store_sql tool with source: "cloud" keeps returning sessions
after they have been deleted everywhere the user can reach:

SELECT COUNT(*) FROM sessions

482, while GET /agents/tasks returns 0 tasks.

These rows are served by POST https://api.githubcopilot.com/agents/analytics/query
and written by chronicle reindex via PUT /agents/sessions/{id},
POST /agents/sessions/{id}/events, and PUT /agents/sessions/{id}/logs.

Every one of those write routes is an upsert or append. No route accepts
DELETE, and POST /agents/analytics/query rejects any non-SELECT
statement.
Once a row exists in the sessions table behind
/agents/analytics/query, no client operation can remove it.

OPTIONS against every route the CLI uses for session data:

Route Allow:
/agents/analytics/query POST
/agents/analytics GET, POST
/agents/sessions GET, POST, PATCH
/agents/sessions/{id} PUT, GET
/agents/sessions/{id}/events GET, POST
/agents/sessions/{id}/logs PUT, GET

DELETE appears on none of them.

Affected version

Copilot CLI 1.0.87 (Linux x64)

Steps to reproduce the behavior

  1. Accumulate CLI sessions with remoteExport enabled (the default).
  2. Delete the corresponding Mission Control tasks:
    DELETE https://api.githubcopilot.com/agents/tasks/{id} (the call the CLI's
    session picker makes), or via github.com/copilot/agent WebUI.
  3. Delete all local session state under ~/.copilot/session-state/.
  4. Set remoteExport to false.
  5. Run session_store_sql with source: "cloud":
    SELECT COUNT(*) FROM sessions

Every previously-exported session is still returned. /chronicle and
cross-session search surface the same rows.

Expected behavior

Sessions deleted from github.com/copilot/tasks, from the CLI session picker,
and from ~/.copilot/session-state/ should stop being returned by
session_store_sql, /chronicle, and cross-session search.

Setting remoteExport: false should also provide some supported way to remove
data already exported — or the retention policy for that data should be
documented.

One of:

  1. A DELETE route for rows in the sessions table — ideally bulk, e.g.
    DELETE /agents/sessions/{id} plus a "delete all my cloud session history"
    operation.
  2. DELETE /agents/tasks/{id} cascading to the matching sessions row.

Additional context

Impact

  1. Deletion is not honored. Session metadata, titles, and summaries remain
    queryable after deletion from every user-reachable surface.
  2. remoteExport: false is not retroactive. It stops new writes but leaves
    every prior row in place, with no documented retention period.
  3. No recourse exists through the CLI, the web UI, or the API.

Related issues

These look like the same gap — deletion never reaching the append-only
/agents/sessions/*/agents/analytics/query pipeline:

Issue Title Relationship
#3811 deleted sessions still in /chronicle insights Closest match — same symptom (local wipe + cloud delete + remoteExport off, yet /chronicle still surfaces deleted sessions); does not identify the route-level cause
#4094 Deleting a session doesn't remove it from session-store.db / VS Code Chat history Self-describes as the same root cause as #3811
#4939 Unable to delete old remote sessions Same family; notes deletion worked in v1.0.55
#3777 /chronicle reindex queues remote backfill despite local-only remote settings Shows remoteExport: false is not fully honored by the sync pipeline

Adding a DELETE route would likely resolve #3811 and #4094 as well.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions