Skip to content

Add attributed MCP OAuth credential storage telemetry - #49392

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/5ea4528bcdcf500c8ffdf1d9c7008ea52112c726
Sep 29, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/5ea4528bcdcf500c8ffdf1d9c7008ea52112c726

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Add attributed MCP OAuth credential storage telemetry

What changed

  • Instrument MCP OAuth loads, saves, deletes, fallback cleanup, and refresh persistence with credential-free storage metrics, distinguishing configured policy from operations on a pinned store.
  • Retain the originating client across background tasks, blocking storage operations, and session recovery, including recovery after startup found no credentials.
  • Preserve typed keyring and lock error categories for metrics and remove raw error details from storage warnings.

Testing

Add tests for policy and pinned-store outcomes, best-effort cleanup failures, wrapped lock errors, and successful or failed refresh persistence without duplicate observations. Add recovery tests that verify client attribution after anonymous startup and across threads with different originators.

## What changed

- Instrument MCP OAuth loads, saves, deletes, fallback cleanup, and refresh persistence with credential-free storage metrics, distinguishing configured policy from operations on a pinned store.
- Retain the originating client across background tasks, blocking storage operations, and session recovery, including recovery after startup found no credentials.
- Preserve typed keyring and lock error categories for metrics and remove raw error details from storage warnings.

## Testing

Add tests for policy and pinned-store outcomes, best-effort cleanup failures, wrapped lock errors, and successful or failed refresh persistence without duplicate observations. Add recovery tests that verify client attribution after anonymous startup and across threads with different originators.

GitOrigin-RevId: 5ea4528bcdcf500c8ffdf1d9c7008ea52112c726
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/5ea4528bcdcf500c8ffdf1d9c7008ea52112c726 branch from ed9f922 to 05ea5f7 Compare September 29, 2026 23:01
@copyberry
copyberry Bot merged commit 05ea5f7 into main Sep 29, 2026
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/5ea4528bcdcf500c8ffdf1d9c7008ea52112c726 branch September 29, 2026 23:02
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 29, 2026

This branch was successfully deployed

1 active deployment
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants