This commit is contained in:
Petr Nyc
2026-09-24 19:17:40 +02:00
parent dcf4cbb64b
commit 434859d178
9 changed files with 253 additions and 45 deletions
+47 -4
View File
@@ -245,8 +245,49 @@ codex_auth_write_gateway_op_token() {
codex_auth_log "MCP Gateway auth preflight: wrote fresh operator token to ${token_file}."
}
codex_auth_reuse_gateway_op_token() {
local cached_token
[[ -r "${MCPGW_OP_TOKEN_FILE}" ]] || return 1
# Inspect expiry locally; the gateway remains responsible for JWT verification.
# Keep the token out of command arguments and diagnostic output.
if ! cached_token="$(python3 - "${MCPGW_OP_TOKEN_FILE}" <<'PY'
import base64
import json
import math
import sys
import time
from pathlib import Path
try:
token = Path(sys.argv[1]).read_text().strip()
header, payload, signature = token.split(".")
if not header or not payload or not signature:
raise ValueError("Incomplete JWT")
claims = json.loads(base64.b64decode(
payload + "=" * (-len(payload) % 4), altchars=b"-_", validate=True
))
expiry = claims["exp"]
valid = (type(expiry) in (int, float) and math.isfinite(expiry)
and expiry > time.time() + 300)
except (OSError, ValueError, KeyError, TypeError):
valid = False
if not valid:
sys.exit(1)
print(token)
PY
)"
then
return 1
fi
export OP_TOKEN="${cached_token}"
export OPERATOR_ACCESS_TOKEN="${cached_token}"
codex_auth_log "MCP Gateway auth preflight: reusing cached operator token (more than 5 minutes remaining)."
}
codex_auth_refresh_gateway_auth() {
local mcpgw_bin op_token_refreshed=0
local mcpgw_bin op_token_ready=0
mcpgw_bin="$(command -v mcpgw 2>/dev/null || true)"
if [[ -n "${mcpgw_bin}" ]]; then
@@ -255,8 +296,10 @@ codex_auth_refresh_gateway_auth() {
codex_auth_log "Warning: mcpgw not found on PATH; skipping MCP Gateway auth refresh."
fi
if codex_auth_prepare_codex_auth && codex_auth_write_gateway_op_token; then
op_token_refreshed=1
if codex_auth_reuse_gateway_op_token; then
op_token_ready=1
elif codex_auth_prepare_codex_auth && codex_auth_write_gateway_op_token; then
op_token_ready=1
else
codex_auth_log "Warning: could not refresh OP token; continuing with existing MCP Gateway token state."
fi
@@ -265,7 +308,7 @@ codex_auth_refresh_gateway_auth() {
return 0
fi
if [[ "${op_token_refreshed}" != "1" ]]; then
if [[ "${op_token_ready}" != "1" ]]; then
codex_auth_log "MCP Gateway auth preflight: skipping token-dependent checks because OP token refresh failed."
return 0
fi