mirror of
https://github.com/openai/codex.git
synced 2026-09-28 16:53:06 +08:00
## What changed Expose the shared `--ws-auth` options on `codex exec-server` for direct WebSocket listeners. Support capability tokens configured by token file or SHA-256 digest, and signed JWT bearer tokens. Validate `Authorization: Bearer TOKEN` before each WebSocket upgrade, rejecting missing or invalid credentials with HTTP 401 when authentication is enabled. Reject listener authentication with stdio, `--remote`, or `forward`. Document the options and connection-time authentication behavior. ## Testing Add CLI integration tests for all three credential configurations, unauthorized upgrade rejection, authenticated RPC initialization and reconnects, invalid configuration, and incompatible transports. GitOrigin-RevId: 941fbd3d43e732c910d29b6f8137077b7c332835