Skip to content

feat(codex): add OAuth fingerprint convergence modes - #10243

Merged
diegosouzapw merged 8 commits into
diegosouzapw:release/v3.8.50from
xz-dev:feat/codex-fingerprint-convergence
Aug 14, 2026
Merged

diegosouzapw merged 8 commits into
diegosouzapw:release/v3.8.50from
xz-dev:feat/codex-fingerprint-convergence

Conversation

@xz-dev

@xz-dev xz-dev commented Aug 13, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • add Sub2API-equivalent Codex OAuth fingerprint convergence modes: off, device, session, and full
  • default unset/invalid modes to session; only explicit off disables convergence
  • preserve the original client identity for explicit off, while compact requests continue to skip identity handling
  • share one precomputed identity across HTTP/WS headers, client_metadata, and nested turn metadata
  • expose and persist the setting only for Codex OAuth connections

Behavior

  • device: converges the account installation ID
  • session: also converges the account session ID and deterministically derives the thread ID from the original client session-id
  • full: converges installation, session, and thread IDs
  • each request receives a fresh turn ID; window ID remains <thread_id>:0
  • HTTP Responses combo targets that resolve to Codex OAuth traverse CodexExecutor, so they receive the same convergence behavior
  • the native Responses WebSocket bridge remains Codex-only and is not a generic combo executor

Validation

  • node --import tsx/esm --test tests/unit/codex-fingerprint-convergence.test.ts tests/unit/executor-codex.test.ts tests/unit/provider-specific-data-schema.test.ts (62/62 passed)
  • node --import tsx/esm --test tests/integration/chat-pipeline.test.ts (28/28 passed)
  • npm exec --yes tsc -- --pretty false -p tsconfig.typecheck-core.json
  • npm run check:file-size
  • npm run check:dead-code
  • npm run check:test-masking
  • Prettier checks for all changed files
  • git diff --check

diegosouzapw and others added 4 commits August 8, 2026 00:08
…ouzapw#189, diegosouzapw#190)

Bumps: nanoid ^3.3.17 (was transitive, now overridden), dompurify ^3.4.13
(with monaco-editor scoped override). Closes Dependabot diegosouzapw#189, diegosouzapw#190.

Remaining diegosouzapw#182-diegosouzapw#188 (js-yaml + mermaid) already closed by diegosouzapw#9651 merge —
awaiting Dependabot re-scan.

npm audit → 0 vulnerabilities.
…egosouzapw#190

Closes Dependabot diegosouzapw#189 (dompurify 3.4.13) and diegosouzapw#190 (nanoid 3.3.17). npm audit → 0.
_tasks is a SEPARATE nested git repo (gitignored). The pattern _tasks/ (trailing
slash) ignores only a directory, not a SYMLINK named _tasks. A self-referential
_tasks symlink can slip in via git add -A and, once pulled, checkout materializes
it over the real _tasks repo (destroying plans/specs/hands-off). Anchored /_tasks
ignores the symlink too, preventing re-capture.
@xz-dev
xz-dev requested a review from diegosouzapw as a code owner August 13, 2026 08:22
@diegosouzapw
diegosouzapw changed the base branch from main to release/v3.8.50 August 13, 2026 13:49
@diegosouzapw

Copy link
Copy Markdown
Owner

Well-architected — shared identity module derives stable installation/session/thread UUIDs for the OAuth fingerprint convergence modes (off/device/session/full). Good to merge.

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
@diegosouzapw
diegosouzapw merged commit 8417ace into diegosouzapw:release/v3.8.50 Aug 14, 2026
4 of 5 checks passed
@diegosouzapw

Copy link
Copy Markdown
Owner

Merged into release/v3.8.50 — thank you @xz-dev! Validated on a combined merge-train (static gates + every affected test + vitest) alongside 9 sibling PRs before landing. We resolved the base-drift conflict on your branch (codexIdentity kept both the fingerprint convergence and #8949's native-Codex helpers) and recorded a file-size rebaseline for providerPageHelpers.ts, which crossed the cap only through the merge of the two independent features.

@diegosouzapw diegosouzapw mentioned this pull request Aug 15, 2026
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
)

* fix(deps): bump nanoid, dompurify for 2 new Dependabot alerts (diegosouzapw#189, diegosouzapw#190)

Bumps: nanoid ^3.3.17 (was transitive, now overridden), dompurify ^3.4.13
(with monaco-editor scoped override). Closes Dependabot diegosouzapw#189, diegosouzapw#190.

Remaining diegosouzapw#182-diegosouzapw#188 (js-yaml + mermaid) already closed by diegosouzapw#9651 merge —
awaiting Dependabot re-scan.

npm audit → 0 vulnerabilities.

* fix(repo): harden .gitignore to also ignore a _tasks symlink (/_tasks)

_tasks is a SEPARATE nested git repo (gitignored). The pattern _tasks/ (trailing
slash) ignores only a directory, not a SYMLINK named _tasks. A self-referential
_tasks symlink can slip in via git add -A and, once pulled, checkout materializes
it over the real _tasks repo (destroying plans/specs/hands-off). Anchored /_tasks
ignores the symlink too, preventing re-capture.

* feat(codex): converge OAuth fingerprints

* test(codex): preserve identity assertions

* fix(codex): preserve explicit off identity

* fix(codex): close fingerprint transport gaps

---------

Co-authored-by: diegosouzapw <diegosouzapw@users.noreply.github.com>
Co-authored-by: Diego Rodrigues de Sa e Souza <diegosouza.pw@outlook.com>
Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>
Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants