Skip to content

Add explicit gateway OAuth sign-in to app-server - #47207

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/a26e116a62c9f3db84dc238a40b7f4e816eb1594
Sep 22, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/a26e116a62c9f3db84dc238a40b7f4e816eb1594

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Add explicit gateway OAuth sign-in to app-server

Why

Clients with a gateway sign-in UI need to control when browser authorization starts and inspect credential readiness before making authenticated requests.

What changed

  • Add initialize.capabilities.explicitGatewayOauth to require explicit login while allowing existing credentials to refresh. Preserve automatic authorization for clients that omit the capability, and prevent later connections from undoing explicit opt-in.
  • Add account/gatewayOAuth/read, account/gatewayOAuth/login, and account/gatewayOAuth/cancel, plus account/gatewayOAuth/changed notifications. Send the authorization URL only to the initiating connection and cancel its login on disconnect.
  • Check gateway authentication before returning cached results from model/list, with restart guidance when provider settings have changed.
  • Update protocol schemas, TypeScript and Python bindings, and document capability probing and the sign-in lifecycle.

Testing

Add tests for passive readiness reads, credential reuse after login, token exchange failures, cancellation and immediate retry, connection ownership, legacy versus explicit login, and model-list authentication checks.

## Why

Clients with a gateway sign-in UI need to control when browser authorization starts and inspect credential readiness before making authenticated requests.

## What changed

- Add `initialize.capabilities.explicitGatewayOauth` to require explicit login while allowing existing credentials to refresh. Preserve automatic authorization for clients that omit the capability, and prevent later connections from undoing explicit opt-in.
- Add `account/gatewayOAuth/read`, `account/gatewayOAuth/login`, and `account/gatewayOAuth/cancel`, plus `account/gatewayOAuth/changed` notifications. Send the authorization URL only to the initiating connection and cancel its login on disconnect.
- Check gateway authentication before returning cached results from `model/list`, with restart guidance when provider settings have changed.
- Update protocol schemas, TypeScript and Python bindings, and document capability probing and the sign-in lifecycle.

## Testing

Add tests for passive readiness reads, credential reuse after login, token exchange failures, cancellation and immediate retry, connection ownership, legacy versus explicit login, and model-list authentication checks.

GitOrigin-RevId: a26e116a62c9f3db84dc238a40b7f4e816eb1594
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/a26e116a62c9f3db84dc238a40b7f4e816eb1594 branch from 7ebfd37 to 064e701 Compare September 22, 2026 06:36
@copyberry
copyberry Bot merged commit 064e701 into main Sep 22, 2026
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/a26e116a62c9f3db84dc238a40b7f4e816eb1594 branch September 22, 2026 06:36
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 22, 2026
@YAOXU-9
YAOXU-9 deployed to issue-triage September 22, 2026 06:44 — with GitHub Actions Active
@YAOXU-9
YAOXU-9 deployed to issue-triage September 22, 2026 06:44 — with GitHub Actions Active
@YAOXU-9
YAOXU-9 deployed to issue-triage September 22, 2026 06:44 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
issue-triage — 064e701b Deployed Sep 22, 2026 by YAOXU-9 via Identify potential duplicates (all issues) #47354
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants