This PR adds support for configs to specify a forced login method (chatgpt or api) as well as a forced chatgpt account id. This lets enterprises uses [managed configs](https://developers.openai.com/codex/security#managed-configuration) to force all employees to use their company's workspace instead of their own or any other. When a workspace id is set, a query param is sent to the login flow which auto-selects the given workspace or errors if the user isn't a member of it. This PR is large but a large % of it is tests, wiring, and required formatting changes. API login with chatgpt forced <img width="1592" height="116" alt="CleanShot 2025-10-19 at 22 40 04" src="https://github.com/user-attachments/assets/560c6bb4-a20a-4a37-95af-93df39d057dd" /> ChatGPT login with api forced <img width="1018" height="100" alt="CleanShot 2025-10-19 at 22 40 29" src="https://github.com/user-attachments/assets/d010bbbb-9c8d-4227-9eda-e55bf043b4af" /> Onboarding with api forced <img width="892" height="460" alt="CleanShot 2025-10-19 at 22 41 02" src="https://github.com/user-attachments/assets/cc0ed45c-b257-4d62-a32e-6ca7514b5edd" /> Onboarding with ChatGPT forced <img width="1154" height="426" alt="CleanShot 2025-10-19 at 22 41 27" src="https://github.com/user-attachments/assets/41c41417-dc68-4bb4-b3e7-3b7769f7e6a1" /> Logging in with the wrong workspace <img width="2222" height="84" alt="CleanShot 2025-10-19 at 22 42 31" src="https://github.com/user-attachments/assets/0ff4222c-f626-4dd3-b035-0b7fe998a046" />
171 lines
5.8 KiB
Rust
171 lines
5.8 KiB
Rust
use std::collections::HashMap;
|
|
use std::path::Path;
|
|
|
|
use app_test_support::McpProcess;
|
|
use app_test_support::to_response;
|
|
use codex_app_server_protocol::GetUserSavedConfigResponse;
|
|
use codex_app_server_protocol::JSONRPCResponse;
|
|
use codex_app_server_protocol::Profile;
|
|
use codex_app_server_protocol::RequestId;
|
|
use codex_app_server_protocol::SandboxSettings;
|
|
use codex_app_server_protocol::Tools;
|
|
use codex_app_server_protocol::UserSavedConfig;
|
|
use codex_core::protocol::AskForApproval;
|
|
use codex_protocol::config_types::ForcedLoginMethod;
|
|
use codex_protocol::config_types::ReasoningEffort;
|
|
use codex_protocol::config_types::ReasoningSummary;
|
|
use codex_protocol::config_types::SandboxMode;
|
|
use codex_protocol::config_types::Verbosity;
|
|
use pretty_assertions::assert_eq;
|
|
use tempfile::TempDir;
|
|
use tokio::time::timeout;
|
|
|
|
const DEFAULT_READ_TIMEOUT: std::time::Duration = std::time::Duration::from_secs(10);
|
|
|
|
fn create_config_toml(codex_home: &Path) -> std::io::Result<()> {
|
|
let config_toml = codex_home.join("config.toml");
|
|
std::fs::write(
|
|
config_toml,
|
|
r#"
|
|
model = "gpt-5-codex"
|
|
approval_policy = "on-request"
|
|
sandbox_mode = "workspace-write"
|
|
model_reasoning_summary = "detailed"
|
|
model_reasoning_effort = "high"
|
|
model_verbosity = "medium"
|
|
profile = "test"
|
|
forced_chatgpt_workspace_id = "12345678-0000-0000-0000-000000000000"
|
|
forced_login_method = "chatgpt"
|
|
|
|
[sandbox_workspace_write]
|
|
writable_roots = ["/tmp"]
|
|
network_access = true
|
|
exclude_tmpdir_env_var = true
|
|
exclude_slash_tmp = true
|
|
|
|
[tools]
|
|
web_search = false
|
|
view_image = true
|
|
|
|
[profiles.test]
|
|
model = "gpt-4o"
|
|
approval_policy = "on-request"
|
|
model_reasoning_effort = "high"
|
|
model_reasoning_summary = "detailed"
|
|
model_verbosity = "medium"
|
|
model_provider = "openai"
|
|
chatgpt_base_url = "https://api.chatgpt.com"
|
|
"#,
|
|
)
|
|
}
|
|
|
|
#[tokio::test(flavor = "multi_thread", worker_threads = 4)]
|
|
async fn get_config_toml_parses_all_fields() {
|
|
let codex_home = TempDir::new().unwrap_or_else(|e| panic!("create tempdir: {e}"));
|
|
create_config_toml(codex_home.path()).expect("write config.toml");
|
|
|
|
let mut mcp = McpProcess::new(codex_home.path())
|
|
.await
|
|
.expect("spawn mcp process");
|
|
timeout(DEFAULT_READ_TIMEOUT, mcp.initialize())
|
|
.await
|
|
.expect("init timeout")
|
|
.expect("init failed");
|
|
|
|
let request_id = mcp
|
|
.send_get_user_saved_config_request()
|
|
.await
|
|
.expect("send getUserSavedConfig");
|
|
let resp: JSONRPCResponse = timeout(
|
|
DEFAULT_READ_TIMEOUT,
|
|
mcp.read_stream_until_response_message(RequestId::Integer(request_id)),
|
|
)
|
|
.await
|
|
.expect("getUserSavedConfig timeout")
|
|
.expect("getUserSavedConfig response");
|
|
|
|
let config: GetUserSavedConfigResponse = to_response(resp).expect("deserialize config");
|
|
let expected = GetUserSavedConfigResponse {
|
|
config: UserSavedConfig {
|
|
approval_policy: Some(AskForApproval::OnRequest),
|
|
sandbox_mode: Some(SandboxMode::WorkspaceWrite),
|
|
sandbox_settings: Some(SandboxSettings {
|
|
writable_roots: vec!["/tmp".into()],
|
|
network_access: Some(true),
|
|
exclude_tmpdir_env_var: Some(true),
|
|
exclude_slash_tmp: Some(true),
|
|
}),
|
|
forced_chatgpt_workspace_id: Some("12345678-0000-0000-0000-000000000000".into()),
|
|
forced_login_method: Some(ForcedLoginMethod::Chatgpt),
|
|
model: Some("gpt-5-codex".into()),
|
|
model_reasoning_effort: Some(ReasoningEffort::High),
|
|
model_reasoning_summary: Some(ReasoningSummary::Detailed),
|
|
model_verbosity: Some(Verbosity::Medium),
|
|
tools: Some(Tools {
|
|
web_search: Some(false),
|
|
view_image: Some(true),
|
|
}),
|
|
profile: Some("test".to_string()),
|
|
profiles: HashMap::from([(
|
|
"test".into(),
|
|
Profile {
|
|
model: Some("gpt-4o".into()),
|
|
approval_policy: Some(AskForApproval::OnRequest),
|
|
model_reasoning_effort: Some(ReasoningEffort::High),
|
|
model_reasoning_summary: Some(ReasoningSummary::Detailed),
|
|
model_verbosity: Some(Verbosity::Medium),
|
|
model_provider: Some("openai".into()),
|
|
chatgpt_base_url: Some("https://api.chatgpt.com".into()),
|
|
},
|
|
)]),
|
|
},
|
|
};
|
|
|
|
assert_eq!(config, expected);
|
|
}
|
|
|
|
#[tokio::test(flavor = "multi_thread", worker_threads = 2)]
|
|
async fn get_config_toml_empty() {
|
|
let codex_home = TempDir::new().unwrap_or_else(|e| panic!("create tempdir: {e}"));
|
|
|
|
let mut mcp = McpProcess::new(codex_home.path())
|
|
.await
|
|
.expect("spawn mcp process");
|
|
timeout(DEFAULT_READ_TIMEOUT, mcp.initialize())
|
|
.await
|
|
.expect("init timeout")
|
|
.expect("init failed");
|
|
|
|
let request_id = mcp
|
|
.send_get_user_saved_config_request()
|
|
.await
|
|
.expect("send getUserSavedConfig");
|
|
let resp: JSONRPCResponse = timeout(
|
|
DEFAULT_READ_TIMEOUT,
|
|
mcp.read_stream_until_response_message(RequestId::Integer(request_id)),
|
|
)
|
|
.await
|
|
.expect("getUserSavedConfig timeout")
|
|
.expect("getUserSavedConfig response");
|
|
|
|
let config: GetUserSavedConfigResponse = to_response(resp).expect("deserialize config");
|
|
let expected = GetUserSavedConfigResponse {
|
|
config: UserSavedConfig {
|
|
approval_policy: None,
|
|
sandbox_mode: None,
|
|
sandbox_settings: None,
|
|
forced_chatgpt_workspace_id: None,
|
|
forced_login_method: None,
|
|
model: None,
|
|
model_reasoning_effort: None,
|
|
model_reasoning_summary: None,
|
|
model_verbosity: None,
|
|
tools: None,
|
|
profile: None,
|
|
profiles: HashMap::new(),
|
|
},
|
|
};
|
|
|
|
assert_eq!(config, expected);
|
|
}
|