Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Codex Agents can use a shared ChatGPT account registered on their Provider. The Provider page supports multiple accounts; the Agent editor can select an existing account or connect another before saving its binding. API-key and server-local CLI sessions keep their existing behavior.
Sign-in runs through the user's local a2wave CLI and a loopback callback, so it works when the platform is hosted on a different computer. The server owns PKCE and token exchange, verifies identity, encrypts credentials, and refreshes them with a lease and revision check. Authenticated teammates may bind accounts; only the creator or an administrator may manage them. Removing an account requires clearing its Agent bindings and revoking its upstream session.
Subscription execution uses Codex app-server with the selected account. Sessions are scoped to that account. A structured authentication failure permits one refresh and continuation of the saved thread within the original deadline; failed recovery cannot replay the original task through generic fallback. Cancellation also covers credential preparation before a CLI process exists.
Includes SQLite and PostgreSQL migrations, API/CLI/OpenAPI support, account-specific model discovery, import/export/clone handling, audit labels, and English/Chinese manuals.
Type of change
Testing checklist
pnpm typecheckpasses for every workspace, including tests; rerun by the pre-push hook on the final commit.pnpm test: 10,728 passing tests including repository scripts, with 2 existing skipped API tests. Workspaces ran sequentially with VITEST_MAX_WORKERS=4 after an unconstrained concurrent run hit three import-hook timeouts; no test timeouts or assertions were relaxed.Additional validation:
pnpm buildpasses; restart-recovery was rerun on the final commit and passes all 4 scenarios.AI assistance disclosure
This implementation was substantially AI-generated and reviewed with parallel agents. The checks above distinguish real account execution from fixtures and protocol tests; the maintainer should review the change before merging.
Additional notes
The aggregate CI result remains red for two reasons: the migrations require the repository's ci-reviewed maintainer label, and dependency auditing reports five high-severity findings in existing locked undici (7.29.0/6.28.0) and brace-expansion (5.0.9). This PR changes no dependency manifests or lockfile; those findings are also reproducible locally.
The account-specific PostgreSQL concurrency paths and real upstream refresh/revocation were not exercised against live services; protocol, locking, rotation, cancellation, and recovery behavior are covered by automated tests. Runtime authentication recovery is limited to one continuation attempt per turn. No production deployment is included.