next
This commit is contained in:
@@ -245,8 +245,49 @@ codex_auth_write_gateway_op_token() {
|
||||
codex_auth_log "MCP Gateway auth preflight: wrote fresh operator token to ${token_file}."
|
||||
}
|
||||
|
||||
codex_auth_reuse_gateway_op_token() {
|
||||
local cached_token
|
||||
|
||||
[[ -r "${MCPGW_OP_TOKEN_FILE}" ]] || return 1
|
||||
# Inspect expiry locally; the gateway remains responsible for JWT verification.
|
||||
# Keep the token out of command arguments and diagnostic output.
|
||||
if ! cached_token="$(python3 - "${MCPGW_OP_TOKEN_FILE}" <<'PY'
|
||||
import base64
|
||||
import json
|
||||
import math
|
||||
import sys
|
||||
import time
|
||||
from pathlib import Path
|
||||
|
||||
try:
|
||||
token = Path(sys.argv[1]).read_text().strip()
|
||||
header, payload, signature = token.split(".")
|
||||
if not header or not payload or not signature:
|
||||
raise ValueError("Incomplete JWT")
|
||||
claims = json.loads(base64.b64decode(
|
||||
payload + "=" * (-len(payload) % 4), altchars=b"-_", validate=True
|
||||
))
|
||||
expiry = claims["exp"]
|
||||
valid = (type(expiry) in (int, float) and math.isfinite(expiry)
|
||||
and expiry > time.time() + 300)
|
||||
except (OSError, ValueError, KeyError, TypeError):
|
||||
valid = False
|
||||
if not valid:
|
||||
sys.exit(1)
|
||||
print(token)
|
||||
PY
|
||||
)"
|
||||
then
|
||||
return 1
|
||||
fi
|
||||
|
||||
export OP_TOKEN="${cached_token}"
|
||||
export OPERATOR_ACCESS_TOKEN="${cached_token}"
|
||||
codex_auth_log "MCP Gateway auth preflight: reusing cached operator token (more than 5 minutes remaining)."
|
||||
}
|
||||
|
||||
codex_auth_refresh_gateway_auth() {
|
||||
local mcpgw_bin op_token_refreshed=0
|
||||
local mcpgw_bin op_token_ready=0
|
||||
mcpgw_bin="$(command -v mcpgw 2>/dev/null || true)"
|
||||
|
||||
if [[ -n "${mcpgw_bin}" ]]; then
|
||||
@@ -255,8 +296,10 @@ codex_auth_refresh_gateway_auth() {
|
||||
codex_auth_log "Warning: mcpgw not found on PATH; skipping MCP Gateway auth refresh."
|
||||
fi
|
||||
|
||||
if codex_auth_prepare_codex_auth && codex_auth_write_gateway_op_token; then
|
||||
op_token_refreshed=1
|
||||
if codex_auth_reuse_gateway_op_token; then
|
||||
op_token_ready=1
|
||||
elif codex_auth_prepare_codex_auth && codex_auth_write_gateway_op_token; then
|
||||
op_token_ready=1
|
||||
else
|
||||
codex_auth_log "Warning: could not refresh OP token; continuing with existing MCP Gateway token state."
|
||||
fi
|
||||
@@ -265,7 +308,7 @@ codex_auth_refresh_gateway_auth() {
|
||||
return 0
|
||||
fi
|
||||
|
||||
if [[ "${op_token_refreshed}" != "1" ]]; then
|
||||
if [[ "${op_token_ready}" != "1" ]]; then
|
||||
codex_auth_log "MCP Gateway auth preflight: skipping token-dependent checks because OP token refresh failed."
|
||||
return 0
|
||||
fi
|
||||
|
||||
Reference in New Issue
Block a user