mirror of
https://github.com/openai/codex.git
synced 2026-09-29 16:57:06 +08:00
## Why MCP OAuth configuration supported a pre-registered client ID but could not supply a client secret for token exchange or refresh. ## What changed - Add `oauth.client_secret` and `codex mcp add --oauth-client-secret`, requiring a nonempty secret and client ID. Persist the secret in server configuration and accept `clientSecret` in plugin configuration. - Pass configured credentials through CLI, app-server, and plugin login flows and token refresh. Require a new login when a configured confidential client's ID differs from stored credentials. - Redact secrets in debug output and keep them out of authorization URLs and persisted OAuth token records. - Invalidate cached OAuth connections when the configured client ID or secret changes. ## Testing Add coverage for configuration validation and round trips, CLI argument redaction and subsequent login, app-server login, connection invalidation, and refresh with `client_secret_basic` and `client_secret_post` in both refresh modes. Verify secret exclusion from token records and reject mismatched client IDs before contacting the provider. GitOrigin-RevId: 85bb0e410e9e68e6cd68eb6359badfc7eac78147