mirror of
https://github.com/openai/codex.git
synced 2026-09-28 08:43:01 +08:00
## Why AWS credential discovery, analytics, and telemetry used clients that did not share the application's network policy. These requests need to honor destination restrictions and permission revocation. ## What changed - Route AWS credential and region HTTP requests through the shared HTTP client, and check the signing destination before loading credentials. Skip discovery for static access keys with an explicit region. - Apply account-scoped policy to Bedrock authentication. Require unrestricted policy for credential exporters and reauthentication commands, and cancel active work when permission is revoked. Document that AWS profile `credential_process` network traffic remains outside the application's HTTP policy. - Send analytics through the authenticated account's HTTP client factory. - Guard OTLP log, trace, and metric exports with revocable permits, disable them under destination restrictions, and make managed HTTP exports cancellable. Suppress global Statsig settings while managed policy is active. ## Testing Add coverage for metadata credential request cancellation, allowed and denied SigV4 destinations, AWS credential precedence and endpoint configuration, and blocked credential exporter recovery. Update telemetry tests for account transitions and managed-policy Statsig suppression. GitOrigin-RevId: d8a2018bfbbe971ec430699b0d3f86a7a9e1e072
38 lines
1021 B
TOML
38 lines
1021 B
TOML
[package]
|
|
edition.workspace = true
|
|
license.workspace = true
|
|
name = "codex-aws-auth"
|
|
version.workspace = true
|
|
|
|
[lib]
|
|
doctest = false
|
|
name = "codex_aws_auth"
|
|
path = "src/lib.rs"
|
|
|
|
[lints]
|
|
workspace = true
|
|
|
|
[dependencies]
|
|
codex-http-client = { workspace = true }
|
|
aws-config = { workspace = true, features = ["credentials-login"] }
|
|
aws-credential-types = { workspace = true }
|
|
aws-sigv4 = { workspace = true }
|
|
aws-smithy-runtime-api = { workspace = true }
|
|
aws-smithy-types = { workspace = true }
|
|
aws-types = { workspace = true }
|
|
bytes = { workspace = true }
|
|
http = { workspace = true }
|
|
http-body = "1.0.1"
|
|
http-body-util = "0.1.3"
|
|
url = { workspace = true }
|
|
thiserror = { workspace = true }
|
|
|
|
[dev-dependencies]
|
|
pretty_assertions = { workspace = true }
|
|
rcgen = { workspace = true }
|
|
rustls = { workspace = true }
|
|
tempfile = { workspace = true }
|
|
tokio-rustls = { workspace = true }
|
|
codex-utils-rustls-provider = { workspace = true }
|
|
tokio = { workspace = true, features = ["io-util", "macros", "net", "rt-multi-thread", "time"] }
|