[openai] 🤖 feat: add project-specific Codex OAuth accounts - #4102
[openai] 🤖 feat: add project-specific Codex OAuth accounts#4102coadler wants to merge 24 commits into
Conversation
|
@codex review |
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1cad0e2ef6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Commit 8dcc53b addresses seven findings:
3942614509 is an intentional compatibility limit, explained in the thread and PR risks. Existing legacy credentials remain until explicit disconnect. Named-only configurations need this version or newer. We do not duplicate rotating credentials or silently substitute another account. Please review the changes and this compatibility rationale. |
This comment has been minimized.
This comment has been minimized.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8dcc53ba2f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Commit 9c6e6e2 addresses the second review:
CI also exposed a metadata issue. The provider response now preserves an unset account selection instead of inventing an explicit default. API-key-only configurations retain direct API controls. |
This comment has been minimized.
This comment has been minimized.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9c6e6e28f5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Commit 6d23a15 addresses the remaining findings:
The tests cover both reconnect/invalidation orders and local-mutex and cross-process lease waiters. |
This comment has been minimized.
This comment has been minimized.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6d23a15fb2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Commit 94c7612 addresses the fourth review:
All reported threads are resolved. Local static checks and 1,436 regression tests pass. The 13 account stories pass at desktop and phone widths. |
This comment has been minimized.
This comment has been minimized.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 94c76122c8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Commit f9b8442 addresses the latest findings:
Local static checks, 1,520 regression tests, and all 13 account stories at desktop and phone widths pass. |
This comment has been minimized.
This comment has been minimized.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f9b8442090
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Commit d7a3f37 addresses 3942811576. All new useCallback wrappers are removed. The component now uses ordinary functions and React Compiler memoization. The installed hooks linter predates React Compiler. A scoped declaration-only suppression handles its callback-stability warnings. The effect retains its complete dependency list, and dependency checking resumes before the effect. Static checks, focused keyboard/provider tests, and all 13 account stories at desktop and phone widths pass. |
This comment has been minimized.
This comment has been minimized.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d7a3f37930
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Commit b7d0905 addresses finding 3942839838. Route availability now requires usable OAuth credentials. Revoked-only configurations permit configured gateway routes. CLI provider detection uses the same rule. Local static checks and 182 focused tests pass. Tests cover legacy slots, named slots, direct priority, and direct overrides. |
This comment has been minimized.
This comment has been minimized.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b7d09057eb
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Commit 2052332 addresses all three findings:
Snapshot capture uses the injected permanent provider store for CLI runs. Public metadata and model credentials derive from the same read. Tests cover account inheritance changes, provider preference changes, wire format, and concurrent provider-file changes. All 732 focused tests and local static checks pass. |
This comment has been minimized.
This comment has been minimized.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2052332c32
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Commit 5cdb0d8 addresses both findings:
All 528 focused tests and local static checks pass. Regressions cover failed writes and reconnects for legacy and named accounts. |
This comment has been minimized.
This comment has been minimized.
|
@codex review Commit e5b47cd fixes PRRT_kwDOPxxmWM6fuvFz. Local static checks and 1,418 regression tests pass. Generated with |
This comment has been minimized.
This comment has been minimized.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e5b47cd11f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Capture route preferences with account snapshots for delayed model creation. Send only the effective numeric context limit to live usage meters. Use current settings after the active stream ends. Co-authored-by: Mux <noreply@coder.com> --- _Generated with `xum` • Model: `openai:gpt-6-astra` • Thinking: `high` • Cost: `$397.18`_ <!-- mux-attribution: model=openai:gpt-6-astra thinking=high costs=397.18 -->
|
@codex review Commit 5076fc7 addresses both findings:
The browser receives no routing snapshot or credentials. Generated with |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5076fc75e7
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Security Review
Here are some automated security review suggestions for this pull request.
Reviewed commit: 5076fc75e7
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
…ounts Derive live context limits from the resolved route and emitted headers. Retain the initiating snapshot for same-session workflow fallback continuations. Keep durable grouped attention on current routing as a new turn. Co-authored-by: Mux <noreply@coder.com> --- _Generated with `xum` • Model: `openai:gpt-6-astra` • Thinking: `high` • Cost: `$409.22`_ <!-- mux-attribution: model=openai:gpt-6-astra thinking=high costs=409.22 -->
|
@codex review Commit 008d2d8 addresses both findings. PRRT_kwDOPxxmWM6fvCMb: Live limits now use the resolved route and emitted Anthropic beta header. PRRT_kwDOPxxmWM6fvCMd: The direct fallback continues one initiating turn in memory. Static checks and 1,743 regression tests pass. Generated with |
This comment has been minimized.
This comment has been minimized.
Store named account secrets under the legacy-redactable credentials field. Preserve account recovery and remove unsafe fields during account writes. --- _Generated with `xum` • Model: `openai:gpt-6-astra` • Thinking: `high` • Cost: `$437.95`_ <!-- mux-attribution: model=openai:gpt-6-astra thinking=high costs=437.95 -->
|
@codex review Commit dbf0bad addresses finding 3945271442 (thread PRRT_kwDOPxxmWM6fvC5D). Named accounts now store tokens and account identities under All 673 targeted tests and Generated with |
This comment has been minimized.
This comment has been minimized.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: dbf0badf56
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Keep one routing snapshot across branch-summary candidates and metadata resolution. Publish the accepted context limit before the first usage event. --- _Generated with `xum` • Model: `openai:gpt-6-astra` • Thinking: `high` • Cost: `$437.95`_ <!-- mux-attribution: model=openai:gpt-6-astra thinking=high costs=437.95 -->
|
@codex review Commit 02b47f8 addresses both findings:
Model construction also captures a default snapshot for matching metadata. Separate operations still use current settings. All 1,733 targeted tests and static checks pass. All 21 account stories pass at desktop and phone widths. Generated with |
This comment has been minimized.
This comment has been minimized.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 02b47f88b3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Keep legacy request identity valid until successful authorization replaces it. Hide account commands when provider policy omits OpenAI. Complete snapshot methods in the disposal-test fixtures. --- _Generated with `xum` • Model: `openai:gpt-6-astra` • Thinking: `high` • Cost: `$437.95`_ <!-- mux-attribution: model=openai:gpt-6-astra thinking=high costs=437.95 -->
|
@codex review Commit 35b6e37 addresses both findings:
Successful authorization replaces the credential identity and clears the alias. Refresh preserves the alias and cross-process identity checks. The missing disposal-test snapshot fixture now matches the required service methods. Generated with |
This comment has been minimized.
This comment has been minimized.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 35b6e3724e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Resolve CLI project account selection through physical paths. Publish fallback model metadata before its first usage event. --- _Generated with `xum` • Model: `openai:gpt-6-astra` • Thinking: `high` • Cost: `$437.95`_ <!-- mux-attribution: model=openai:gpt-6-astra thinking=high costs=437.95 -->
|
@codex review This update addresses both findings:
Fallback updates preserve stream parts, tool timing, and replay state. Reconnect also restores the active fallback metadata. All 2,139 targeted tests and static checks pass. All 23 account stories pass at desktop and phone widths. Generated with |
|
Codex Review: Didn't find any major issues. Hooray! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
This comment has been minimized.
This comment has been minimized.
Include the accepted-model update in compaction fallback event expectations. Keep the existing reset-order and prefix-invalidation assertions. --- _Generated with `xum` • Model: `openai:gpt-6-astra` • Thinking: `high` • Cost: `$437.95`_ <!-- mux-attribution: model=openai:gpt-6-astra thinking=high costs=437.95 -->
|
@codex review This update changes two test expectation lines only. Production code remains identical to approved commit Compaction fallback tests now expect The CI failures reproduce locally before this correction. All 832 stream and session regressions now pass. Generated with |
|
Codex Review: Didn't find any major issues. Bravo. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Summary
Support multiple Codex OAuth accounts with a global default and project-specific account selection.
Background
Projects can require different ChatGPT accounts. A single saved login forces users to reconnect when they switch projects.
Implementation
Risks
Incorrect account routing can charge the wrong account. Explicit selection and missing-account errors prevent silent account substitution.
Concurrent refreshes can invalidate credentials. Account-specific leases and conditional writes protect token rotation and account removal.
Older versions use only the legacy account. Named-only configurations require this version or newer. Existing legacy credentials remain until explicit disconnect.
We do not duplicate rotating credentials for downgrade support. Duplicate refresh tokens can invalidate named accounts across versions.
Live OpenAI authorization remains untested.
Generated with
xum• Model:openai:gpt-6-astra• Thinking:high• Cost:$226.69