Skip to content

Bind remote-control sessions to their authentication owner - #44341

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/5e6ecd23588aab1e2e6168a21f575fb24bbb341c
Sep 9, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/5e6ecd23588aab1e2e6168a21f575fb24bbb341c

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Bind remote-control sessions to their authentication owner

Why

Remote-control connections and queued operations must not carry over to a different signed-in user or account. Token refreshes for the same identity should preserve the live relay connection.

What changed

  • Scope relay state and authentication recovery to a login lifetime. Retire the session on logout or identity changes and leave remote control disabled until enabled again.
  • Reject stale incoming messages and queued RPCs, and cancel pending remote-control operations when their authentication owner changes.
  • Start replacement sessions with fresh client, replay, and enrollment state, and prevent retired sessions from publishing status into their replacements.
  • Serialize enrollment and preference persistence across sessions, retaining write permits through caller cancellation and draining admitted writes on shutdown.

Testing

Add regression coverage for same-owner refreshes, user and account changes, stale pairing and client-revocation work, unauthorized enrollment recovery after logging in again, and persistence during cancellation.

## Why

Remote-control connections and queued operations must not carry over to a different signed-in user or account. Token refreshes for the same identity should preserve the live relay connection.

## What changed

- Scope relay state and authentication recovery to a login lifetime. Retire the session on logout or identity changes and leave remote control disabled until enabled again.
- Reject stale incoming messages and queued RPCs, and cancel pending remote-control operations when their authentication owner changes.
- Start replacement sessions with fresh client, replay, and enrollment state, and prevent retired sessions from publishing status into their replacements.
- Serialize enrollment and preference persistence across sessions, retaining write permits through caller cancellation and draining admitted writes on shutdown.

## Testing

Add regression coverage for same-owner refreshes, user and account changes, stale pairing and client-revocation work, unauthorized enrollment recovery after logging in again, and persistence during cancellation.

GitOrigin-RevId: 5e6ecd23588aab1e2e6168a21f575fb24bbb341c
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/5e6ecd23588aab1e2e6168a21f575fb24bbb341c branch from 3874c78 to 1bff94e Compare September 9, 2026 23:59
@copyberry
copyberry Bot merged commit 1bff94e into main Sep 9, 2026
1 check passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/5e6ecd23588aab1e2e6168a21f575fb24bbb341c branch September 9, 2026 23:59
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 9, 2026

This branch was previously deployed

1 inactive deployment
issue-triage — 1bff94ed Deployed Sep 10, 2026 by apurban810-creator via Generate label suggestions #44108
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants