mirror of
https://github.com/openai/codex.git
synced 2026-09-29 16:57:06 +08:00
Fail closed when workload identity initialization fails (#38424)
## What changed - Treat workload identity environment markers as an explicit authentication selection, even when another process credential is present. - Return initialization errors from `AuthManager` and propagate them through commands and services instead of continuing with an unusable authentication state. - Make `codex login status` validate workload identity, keep the TUI on an embedded app server for local workload identity, and reject workload identity in `codex mcp-server`, where it is unsupported. ## Testing - Cover workload identity precedence and partial configuration errors. - Verify login status reports an unreadable identity assertion and app-server routing enforces the supported workload identity topology. GitOrigin-RevId: efc6b6b4cd4d61652617de82aaa3d7ffc75d6618
This commit is contained in:
@@ -117,7 +117,7 @@ async fn run_main(arg0_paths: Arg0DispatchPaths) -> anyhow::Result<()> {
|
||||
let state_db = init_state_db(&config).await;
|
||||
|
||||
let auth_manager =
|
||||
AuthManager::shared_from_config(&config, /*enable_codex_api_key_env*/ false).await;
|
||||
AuthManager::shared_from_config(&config, /*enable_codex_api_key_env*/ false).await?;
|
||||
let local_runtime_paths = ExecServerRuntimePaths::from_optional_paths(
|
||||
config.codex_self_exe.clone(),
|
||||
config.codex_linux_sandbox_exe.clone(),
|
||||
|
||||
Reference in New Issue
Block a user