64a01ab31e
Review finding from @kartik-mem0 on this PR. Only the explicit slash commands set a source. Automatic recall at entry.ts:80, the capture path, the memory tools and deletion all go through the same client constructed at entry.ts:31 with no attribution, so everything except the commands still reached the platform as generic SDK traffic. That is most of the plugin's traffic. Identity is now stamped once on the shared client. Deliberately by mutating client.headers rather than through the SDK's MEM0_SOURCE environment support: this package pins mem0ai ^3.0.7, the installed build has no such support, and setting an environment variable it does not read would have looked like a fix and changed nothing. Every request method in the published client sends this.headers, so this covers all of them and keeps working when the SDK gains the env path. Set-once and append-only are preserved, so a wrapper that already named a surface keeps it and the client stack accumulates rather than being replaced. PLATFORM_SOURCE moves into the new module and commands.ts imports it; the body source stays on those two calls because that is what the backend reads when the header is absent. Five tests for the header contract, plus the existing suite: 94 pi-agent tests pass and the tsup DTS build is clean. Python side 307 passed, 8 skipped. Claude-Session: https://claude.ai/code/session_01C7tEmH86HAr7GoAAKCEHZb