-
Notifications
You must be signed in to change notification settings - Fork 1.3k
feat(chatgpt-unblock): route an app that opened before opencodex #6381
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
lcxhh521
wants to merge
12
commits into
lidge-jun:dev
Choose a base branch
from
lcxhh521:feat/chatgpt-unblock-ready-watcher
base: dev
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
+4,760
−122
Open
Changes from all commits
Commits
Show all changes
12 commits
Select commit
Hold shift + click to select a range
4e0e8f4
feat(chatgpt): add experimental macOS app-server quota-gate shim
lidge-jun 98194c3
feat(chatgpt): carry the local-CA send-unblock intercept (split from …
lidge-jun 51a92cf
docs(structure): keep runtime.md within its 600-line budget
lidge-jun f89bffc
perf(chatgpt): load the send-unblock intercept only when it is enabled
lidge-jun 33f271c
feat(chatgpt): route an app that opened before opencodex
lcxhh521 eb6ab8a
docs(chatgpt): document the readiness trigger and the full explicit-l…
lcxhh521 71bce16
Merge dev into the ready-marker watcher branch
lcxhh521 c74fa3c
fix(chatgpt): count the web snapshot's used_percent as plain-quota ev…
lcxhh521 4d80aaa
fix(chatgpt): report a failed relaunch and a held lock from the launc…
lcxhh521 b185b4e
Merge dev into the ready-marker watcher branch
lcxhh521 9c6dc70
test(chatgpt): prove the launch script drops an inherited CODEX_CLI_PATH
lcxhh521 755161b
Merge dev into the ready-marker watcher branch
lcxhh521 File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,51 @@ | ||
| import { X509Certificate } from "node:crypto"; | ||
| import { existsSync, mkdtempSync, readFileSync, rmSync } from "node:fs"; | ||
| import { tmpdir } from "node:os"; | ||
| import { join } from "node:path"; | ||
| import { defaultSecurityRunner, loginKeychainPath, type SecurityRunner } from "../../claude/intercept/picker-trust"; | ||
|
|
||
| /** | ||
| * Whether macOS trusts the intercept CA the ChatGPT listener's leaf is issued from. | ||
| * | ||
| * Without that trust every request the app sends to chatgpt.com fails certificate | ||
| * verification, which the app does not report: account, usage and settings pages just stay | ||
| * empty. `ocx chatgpt status` surfaces this state so the cause is visible. Trust is matched by | ||
| * the CA's SHA-1 fingerprint in the user's exported trust settings, so a different or | ||
| * regenerated certificate with the same name never counts. | ||
| */ | ||
|
|
||
| export type ChatgptCaTrust = "trusted" | "untrusted" | "missing" | "unknown" | "unsupported"; | ||
|
|
||
| export function certificateSha1(pem: string): string { | ||
| return new X509Certificate(pem).fingerprint.replace(/:/g, "").toUpperCase(); | ||
| } | ||
|
|
||
| export async function inspectChatgptCaTrust( | ||
| caPath: string, | ||
| run: SecurityRunner = defaultSecurityRunner, | ||
| platform: NodeJS.Platform = process.platform, | ||
| ): Promise<ChatgptCaTrust> { | ||
| if (platform !== "darwin") return "unsupported"; | ||
| if (!existsSync(caPath)) return "missing"; | ||
| let dir: string | undefined; | ||
| try { | ||
| const sha1 = certificateSha1(readFileSync(caPath, "utf8")); | ||
| dir = mkdtempSync(join(tmpdir(), "ocx-chatgpt-trust-")); | ||
| const file = join(dir, "trust-settings.plist"); | ||
| const exported = await run(["trust-settings-export", file]); | ||
| if (exported.code !== 0) { | ||
| // A user domain with no trust settings at all cannot be exported; that is plain "untrusted". | ||
| return /no trust settings/i.test(`${exported.stdout}${exported.stderr}`) ? "untrusted" : "unknown"; | ||
| } | ||
| return readFileSync(file, "utf8").includes(`<key>${sha1}</key>`) ? "trusted" : "untrusted"; | ||
| } catch { // no-excuse-ok: catch -- unreadable certificate or trust settings are no evidence of trust. | ||
| return "unknown"; | ||
| } finally { | ||
| if (dir) rmSync(dir, { recursive: true, force: true }); | ||
| } | ||
| } | ||
|
|
||
| /** The command that restores trust; it prompts for the login password, so only the user runs it. */ | ||
| export function chatgptCaTrustCommand(caPath: string): string { | ||
| return `security add-trusted-cert -r trustRoot -p ssl -k "${loginKeychainPath()}" "${caPath}"`; | ||
| } |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.