Skip to content

Add OAuth credential management for model provider gateways - #46318

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/e0c17f1eab7acca378a14b2d00b80940d8542e47
Sep 17, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/e0c17f1eab7acca378a14b2d00b80940d8542e47

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Add OAuth credential management for model provider gateways

What changed

  • Export GatewayAuthConfig and GatewayAuthManager with PKCE browser sign-in, loopback callbacks, cached token resolution, and refresh after expiry or rejection.
  • Store gateway credentials in a dedicated encrypted namespace with an independent keyring key. Serialize token exchanges and persistence across processes, preserve refresh rotations after caller cancellation, and retain pending credentials when saving fails.
  • Validate OAuth endpoints and token responses, disable token-request redirects and logging, and redact sensitive error details.

Testing

Add tests covering browser authorization, callback state validation and cleanup, concurrent refreshes, cancellation, failed-save recovery, storage isolation, endpoint validation, and credential redaction.

## What changed

- Export `GatewayAuthConfig` and `GatewayAuthManager` with PKCE browser sign-in, loopback callbacks, cached token resolution, and refresh after expiry or rejection.
- Store gateway credentials in a dedicated encrypted namespace with an independent keyring key. Serialize token exchanges and persistence across processes, preserve refresh rotations after caller cancellation, and retain pending credentials when saving fails.
- Validate OAuth endpoints and token responses, disable token-request redirects and logging, and redact sensitive error details.

## Testing

Add tests covering browser authorization, callback state validation and cleanup, concurrent refreshes, cancellation, failed-save recovery, storage isolation, endpoint validation, and credential redaction.

GitOrigin-RevId: e0c17f1eab7acca378a14b2d00b80940d8542e47
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/e0c17f1eab7acca378a14b2d00b80940d8542e47 branch from 9dc9ec8 to a129392 Compare September 17, 2026 23:35
@copyberry
copyberry Bot merged commit a129392 into main Sep 17, 2026
1 check passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/e0c17f1eab7acca378a14b2d00b80940d8542e47 branch September 17, 2026 23:35
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 17, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant