docs(cli): explain shim-free Codex token injection boundaries (#2713) - #3208
Conversation
Records what does and does not carry OPENCODEX_API_AUTH_TOKEN into a Codex process launched independently of the proxy, why EnvironmentFile= on the proxy unit cannot, and where ocx doctor reports the broken env_key launch path (landed in #2844).
|
✅ Deterministic PR hygiene checks passed. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Team Run ID: 📒 Files selected for processing (3)
📝 WalkthroughWalkthroughThe pull request adds WP7 planning and audit records, then documents shim-free Codex token injection in the CLI lifecycle reference. It describes process boundaries, supported and unsupported injection methods, shim replacement after Codex upgrades, and ChangesWP7 token injection documentation
Estimated code review effort: 1 (Trivial) | ~5 minutes Suggested reviewers: ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f5080c3a89
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| the cron line, or an `Environment=`/`EnvironmentFile=` on the systemd unit that launches | ||
| **Codex** (not the proxy). Point it at the existing token file; do not copy the value into |
There was a problem hiding this comment.
Do not point EnvironmentFile at the raw token file
For the documented systemd-unit path, this wording directs users to set EnvironmentFile=$OPENCODEX_HOME/service-api-token, but writeServiceApiTokenFile() writes only the raw token plus a newline (src/lib/service-secrets.ts:52-65), while systemd's EnvironmentFile= format requires newline-separated variable assignments. Consequently the Codex unit receives no OPENCODEX_API_AUTH_TOKEN and still fails with the missing-variable error. Document an ExecStart wrapper that reads and exports the raw file, or require a separate protected OPENCODEX_API_AUTH_TOKEN=... environment file instead.
AGENTS.md reference: docs-site/AGENTS.md:L7-L10
Useful? React with 👍 / 👎.
…jun#2713) (lidge-jun#3208) Records what does and does not carry OPENCODEX_API_AUTH_TOKEN into a Codex process launched independently of the proxy, why EnvironmentFile= on the proxy unit cannot, and where ocx doctor reports the broken env_key launch path (landed in lidge-jun#2844). Co-authored-by: jun <jun@lidge.dev>
…jun#2713) (lidge-jun#3208) Records what does and does not carry OPENCODEX_API_AUTH_TOKEN into a Codex process launched independently of the proxy, why EnvironmentFile= on the proxy unit cannot, and where ocx doctor reports the broken env_key launch path (landed in lidge-jun#2844). Co-authored-by: jun <jun@lidge.dev>
Summary
ocx doctordiagnostic landed in fix(doctor): diagnose the broken Codex env_key launch path #2844. New "Token injection without the shim" subsection underocx codex-shiminreference/cli/lifecycle.md.env_keynames a variable but does not create it; the shim or an export in the process that launches Codex (shell profile, cron line, a unit that starts Codex) carriesOPENCODEX_API_AUTH_TOKEN;EnvironmentFile=/OCX_API_TOKEN_FILEonopencodex-proxy.serviceconfigures only the proxy and never reaches an independentcodex exec.config.toml, and names theocx doctor"Codex env_key launch readiness" line as the detector. No new commands or config keys; a first-classocx codex-envis declined per the maintainer review (asystemd --userdefault does not fit root-owned servers, and the launcher path is the exact hole the issue reports).Closes #2713
Verification
bun run privacy:scanpassed;bun run skill:surface:checkcurrent (no CLI surface change).bun test tests/doctor-codex-envkey-readiness.test.ts→ 8 pass (sanity for the referenced diagnostic; no code change).Checklist
Summary by CodeRabbit
ocx doctor.