Skip to content

Preserve snapshots before Codex login rewrites auth#21

Merged
NagyVikt merged 1 commit intomainfrom
agent/codex/preserve-codex-login-snapshots-2026-05-05-11-42
May 5, 2026
Merged

Preserve snapshots before Codex login rewrites auth#21
NagyVikt merged 1 commit intomainfrom
agent/codex/preserve-codex-login-snapshots-2026-05-05-11-42

Conversation

@NagyVikt
Copy link
Copy Markdown
Collaborator

@NagyVikt NagyVikt commented May 5, 2026

Automated by gx branch finish (PR flow).

The login hook restores the pinned session before running Codex. When auth.json was still a symlink to the saved snapshot and the pinned snapshot already matched, restore skipped activation and left the symlink in place. Official codex login could then write through the symlink and replace the saved admin snapshot with the newly logged-in account.

Materialize auth.json during restore before the identity-match early return so Codex writes only to the working auth file. The regression keeps the snapshot symlink case and simulates an official login writing Odin credentials after restore.

Constraint: Existing installations may still have symlinked auth.json from older versions.

Rejected: Only rely on syncExternalAuthSnapshotIfNeeded after Codex exits | the snapshot is already overwritten by then.

Confidence: high

Scope-risk: narrow

Directive: Restore-session must keep auth.json as a regular file before launching Codex.

Tested: npm test

Tested: npm test -- --test-name-pattern 'restoreSessionSnapshotIfNeeded materializes matching auth symlink'

Tested: openspec validate --specs
@NagyVikt NagyVikt merged commit d8e8ac7 into main May 5, 2026
@NagyVikt NagyVikt deleted the agent/codex/preserve-codex-login-snapshots-2026-05-05-11-42 branch May 5, 2026 09:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant