Repository navigation
Centralize OAuth login and refresh handling with safer diagnostics - #46300
Merged
copyberry[bot] merged 1 commit intoSep 17, 2026
Conversation
…46300) ## Why Login and token refresh have separate OAuth request and error handling. Token endpoint errors can echo credentials, and JSON decoding errors can expose token values in diagnostics. ## What changed - Extract authorization URL construction, callback validation, PKCE, token grants, and error handling into a shared `oauth` module in `codex-rs/login`. - Route authorization-code exchange and ChatGPT refresh through `OAuthClient`, retaining form and JSON encoding respectively and caller-owned HTTP and credential recovery policies. - Redact echoed request secrets from rejection details and request IDs, redact sensitive transport URL fields, and replace token decoding errors with a generic error. Preserve original error codes for refresh failure classification. - Keep callback state validation ahead of codes and provider errors, with the existing onboarding suffix handled by the login server. ## Testing Add coverage for PKCE binding, request encoding and headers, callback state rejection, credential redaction, oversized or unreadable error bodies, and preservation of stored and cached credentials after transient refresh failures. GitOrigin-RevId: d0a9583b99e24f5aafb751acd1e7200e2261a0e4
copyberry
Bot
force-pushed
the
copyberry/codex-internal-to-codex-oss/d0a9583b99e24f5aafb751acd1e7200e2261a0e4
branch
from
September 17, 2026 20:17
63ff59a to
8f73cde
Compare
copyberry
Bot
deleted the
copyberry/codex-internal-to-codex-oss/d0a9583b99e24f5aafb751acd1e7200e2261a0e4
branch
September 17, 2026 20:17
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Centralize OAuth login and refresh handling with safer diagnostics
Why
Login and token refresh have separate OAuth request and error handling. Token endpoint errors can echo credentials, and JSON decoding errors can expose token values in diagnostics.
What changed
oauthmodule incodex-rs/login.OAuthClient, retaining form and JSON encoding respectively and caller-owned HTTP and credential recovery policies.Testing
Add coverage for PKCE binding, request encoding and headers, callback state rejection, credential redaction, oversized or unreadable error bodies, and preservation of stored and cached credentials after transient refresh failures.