Skip to content

feat(providers): add shared ChatGPT accounts for Codex - #122

Draft
aredddd wants to merge 1 commit into
LilithGames:mainfrom
aredddd:codex/chatgpt-subscription-accounts
Draft

aredddd wants to merge 1 commit into
LilithGames:mainfrom
aredddd:codex/chatgpt-subscription-accounts

Conversation

@aredddd

@aredddd aredddd commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Codex Agents can use a shared ChatGPT account registered on their Provider. The Provider page supports multiple accounts; the Agent editor can select an existing account or connect another before saving its binding. API-key and server-local CLI sessions keep their existing behavior.

Sign-in runs through the user's local a2wave CLI and a loopback callback, so it works when the platform is hosted on a different computer. The server owns PKCE and token exchange, verifies identity, encrypts credentials, and refreshes them with a lease and revision check. Authenticated teammates may bind accounts; only the creator or an administrator may manage them. Removing an account requires clearing its Agent bindings and revoking its upstream session.

Subscription execution uses Codex app-server with the selected account. Sessions are scoped to that account. A structured authentication failure permits one refresh and continuation of the saved thread within the original deadline; failed recovery cannot replay the original task through generic fallback. Cancellation also covers credential preparation before a CLI process exists.

Includes SQLite and PostgreSQL migrations, API/CLI/OpenAPI support, account-specific model discovery, import/export/clone handling, audit labels, and English/Chinese manuals.

Type of change

  • New feature (non-breaking change that adds functionality)

Testing checklist

  • Lint: 0 errors, 739 warnings (baseline: 740); explicit repository paths supplied because the worktree's parent directory is excluded by Biome's root glob.
  • pnpm typecheck passes for every workspace, including tests; rerun by the pre-push hook on the final commit.
  • pnpm test: 10,728 passing tests including repository scripts, with 2 existing skipped API tests. Workspaces ran sequentially with VITEST_MAX_WORKERS=4 after an unconstrained concurrent run hit three import-hook timeouts; no test timeouts or assertions were relaxed.
  • E2E updated for Provider login and Agent selection/save; both new cases pass.
  • User-facing docs, both locales, and the in-app manuals updated.

Additional validation:

  • Real ChatGPT consent completed through the built CLI. Model discovery returned five account-authorized models. Two actual Agent turns using the locked Codex 0.154.0 binary and gpt-5.6-luna executed a terminal tool and retained conversation context. After the final session-isolation fix, a second two-turn acceptance run confirmed the account-scoped session, completed tool records, and persisted usage.
  • Isolated HTTP + SQLite binding checks passed 14/14: top-level and chain bindings, updates, unbinding, cloning/export/import, and referenced-account deletion.
  • Full Playwright run: 189 passed, 16 skipped, 8 failed in pre-existing Runs/session-drawer tests. All eight reproduced at the same assertions in a separate archive of unchanged main (27bf128), with a new database and fake CLIs. They expect the previous Runs endpoint/drawer navigation. The failures are reported rather than waived or hidden.
  • PostgreSQL schema regeneration produced identical output; secret scanning, architecture, file-size, and Docker-context gates pass.
  • Coverage suites pass: API 87.99% lines (7,622 passing tests), CLI 88.44%, Web 59.54%. The final API coverage run used four workers.
  • pnpm build passes; restart-recovery was rerun on the final commit and passes all 4 scenarios.
  • The final commit's GitHub CI passes lint, typecheck, all four API shards, CLI/Web tests, PostgreSQL schema generation, SCM storage integration, secret scanning, and license inventory.

AI assistance disclosure

This implementation was substantially AI-generated and reviewed with parallel agents. The checks above distinguish real account execution from fixtures and protocol tests; the maintainer should review the change before merging.

Additional notes

The aggregate CI result remains red for two reasons: the migrations require the repository's ci-reviewed maintainer label, and dependency auditing reports five high-severity findings in existing locked undici (7.29.0/6.28.0) and brace-expansion (5.0.9). This PR changes no dependency manifests or lockfile; those findings are also reproducible locally.

The account-specific PostgreSQL concurrency paths and real upstream refresh/revocation were not exercised against live services; protocol, locking, rotation, cancellation, and recovery behavior are covered by automated tests. Runtime authentication recovery is limited to one continuation attempt per turn. No production deployment is included.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant