Skip to content

Centralize OAuth login and refresh handling with safer diagnostics - #46300

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/d0a9583b99e24f5aafb751acd1e7200e2261a0e4
Sep 17, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/d0a9583b99e24f5aafb751acd1e7200e2261a0e4

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Centralize OAuth login and refresh handling with safer diagnostics

Why

Login and token refresh have separate OAuth request and error handling. Token endpoint errors can echo credentials, and JSON decoding errors can expose token values in diagnostics.

What changed

  • Extract authorization URL construction, callback validation, PKCE, token grants, and error handling into a shared oauth module in codex-rs/login.
  • Route authorization-code exchange and ChatGPT refresh through OAuthClient, retaining form and JSON encoding respectively and caller-owned HTTP and credential recovery policies.
  • Redact echoed request secrets from rejection details and request IDs, redact sensitive transport URL fields, and replace token decoding errors with a generic error. Preserve original error codes for refresh failure classification.
  • Keep callback state validation ahead of codes and provider errors, with the existing onboarding suffix handled by the login server.

Testing

Add coverage for PKCE binding, request encoding and headers, callback state rejection, credential redaction, oversized or unreadable error bodies, and preservation of stored and cached credentials after transient refresh failures.

…46300)

## Why

Login and token refresh have separate OAuth request and error handling. Token endpoint errors can echo credentials, and JSON decoding errors can expose token values in diagnostics.

## What changed

- Extract authorization URL construction, callback validation, PKCE, token grants, and error handling into a shared `oauth` module in `codex-rs/login`.
- Route authorization-code exchange and ChatGPT refresh through `OAuthClient`, retaining form and JSON encoding respectively and caller-owned HTTP and credential recovery policies.
- Redact echoed request secrets from rejection details and request IDs, redact sensitive transport URL fields, and replace token decoding errors with a generic error. Preserve original error codes for refresh failure classification.
- Keep callback state validation ahead of codes and provider errors, with the existing onboarding suffix handled by the login server.

## Testing

Add coverage for PKCE binding, request encoding and headers, callback state rejection, credential redaction, oversized or unreadable error bodies, and preservation of stored and cached credentials after transient refresh failures.

GitOrigin-RevId: d0a9583b99e24f5aafb751acd1e7200e2261a0e4
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/d0a9583b99e24f5aafb751acd1e7200e2261a0e4 branch from 63ff59a to 8f73cde Compare September 17, 2026 20:17
@copyberry
copyberry Bot merged commit 8f73cde into main Sep 17, 2026
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/d0a9583b99e24f5aafb751acd1e7200e2261a0e4 branch September 17, 2026 20:17
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 17, 2026

This branch was successfully deployed

1 active deployment
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants