Compare commits
2
Commits
c480dd012e
...
434859d178
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
434859d178 | ||
|
|
dcf4cbb64b |
+97
-37
@@ -1,9 +1,9 @@
|
||||
model_provider = "openai"
|
||||
model = "gpt-5.6-luna"
|
||||
model = "gpt-6-astra"
|
||||
openai_base_url = "http://127.0.0.1:8787/v1"
|
||||
|
||||
# Work around Headroom 0.25.0 stripping Codex model metadata.
|
||||
model_catalog_json = "/Users/jetpac/.codex-test/models_cache.json"
|
||||
model_catalog_json = "/Users/jetpac/.codex/models_cache.json"
|
||||
|
||||
# doc: https://developers.openai.com/codex/config-advanced
|
||||
# https://developers.openai.com/codex/config-reference
|
||||
@@ -32,7 +32,7 @@ trust_level = "trusted"
|
||||
|
||||
# sandbox_mode = "workspace-write"
|
||||
personality = "pragmatic"
|
||||
model_reasoning_effort = "low"
|
||||
model_reasoning_effort = "xhigh"
|
||||
plan_mode_reasoning_effort = "xhigh"
|
||||
|
||||
|
||||
@@ -53,16 +53,18 @@ memories = true
|
||||
# remote_control = true
|
||||
|
||||
[agents]
|
||||
max_threads = 20
|
||||
max_threads = 6
|
||||
max_depth = 2
|
||||
|
||||
[tui]
|
||||
alternate_screen = "always"
|
||||
status_line = ["model-with-reasoning", "current-dir", "git-branch", "run-state", "codex-version", "context-remaining"]
|
||||
pet = "seedy"
|
||||
animations = false
|
||||
|
||||
[tui.model_availability_nux]
|
||||
"gpt-5.5" = 4
|
||||
gpt-6-astra = 4
|
||||
|
||||
[sandbox_workspace_write]
|
||||
network_access = true
|
||||
@@ -466,20 +468,12 @@ command = "node"
|
||||
args = ["/Users/jetpac/Documents/codex-tools/MCPs/notmuch/dist/index.js"]
|
||||
startup_timeout_sec = 30.0
|
||||
|
||||
[mcp_servers.notmuch.tools.notmuch_count_messages]
|
||||
approval_mode = "approve"
|
||||
|
||||
[mcp_servers.notmuch.tools.notmuch_get_message]
|
||||
approval_mode = "approve"
|
||||
|
||||
[mcp_servers.notmuch.tools.notmuch_get_thread]
|
||||
approval_mode = "approve"
|
||||
|
||||
[mcp_servers.notmuch.tools.notmuch_list_tags]
|
||||
approval_mode = "approve"
|
||||
|
||||
[mcp_servers.notmuch.tools.notmuch_search_threads]
|
||||
approval_mode = "approve"
|
||||
[mcp_servers.notmuch.tools]
|
||||
notmuch_count_messages = { approval_mode = "approve" }
|
||||
notmuch_get_message = { approval_mode = "approve" }
|
||||
notmuch_get_thread = { approval_mode = "approve" }
|
||||
notmuch_list_tags = { approval_mode = "approve" }
|
||||
notmuch_search_threads = { approval_mode = "approve" }
|
||||
|
||||
[mcp_servers.mail-send]
|
||||
command = "node"
|
||||
@@ -514,7 +508,7 @@ jenkins_get_job_config = { approval_mode = "approve" }
|
||||
jenkins_get_log = { approval_mode = "approve" }
|
||||
jenkins_get_node = { approval_mode = "approve" }
|
||||
jenkins_runtime = { approval_mode = "approve" }
|
||||
# jenkins_start_build = { approval_mode = "approve" }
|
||||
jenkins_start_build = { approval_mode = "approve" }
|
||||
jenkins_get_queue_item = { approval_mode = "approve" }
|
||||
jenkins_get_stage_log = { approval_mode = "approve" }
|
||||
jenkins_get_test_results = { approval_mode = "approve" }
|
||||
@@ -1174,13 +1168,77 @@ trust_level = "trusted"
|
||||
[projects."/Users/jetpac/Documents/OSD/nginx-update-july-2026"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/Documents/codex/2026-08-14/chrome-tabs-the-user-has-the"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/Documents/OSD/slaps-scan"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Applications/ChatGPT.app/Contents"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/PycharmProjects/ips-buildmachine-update/solaris/akidr"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/private/var/tmp/q/oci-desktop-service-shepherd"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/PycharmProjects/userland-pipeline/gkap/testing.sme"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/Documents/OSD/component-update-september-2026"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/Documents/quim-codex-approval"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/Documents/codex-auto-access"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/Documents/lsu"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/Documents/java-build"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/Documents/OSD"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/Documents/OSD/build-instance"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/Documents/OSD/component-update-september-2026/calico-scm"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/PycharmProjects/ips-buildmachine-update/solaris/ips/update-buildmachines"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/Documents/OSD/component-update-september-2026/tigera-operator-new"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/.config/karabiner"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/PycharmProjects/ips-esu"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/PycharmProjects/on-esu"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/PycharmProjects/ul-esu"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/.config/kitty"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[projects."/Users/jetpac/Documents/ansible"]
|
||||
trust_level = "trusted"
|
||||
|
||||
[marketplaces.openai-bundled]
|
||||
last_updated = "2026-08-03T08:15:24Z"
|
||||
source_type = "local"
|
||||
source = "/Users/jetpac/.codex/.tmp/bundled-marketplaces/openai-bundled"
|
||||
|
||||
[marketplaces.openai-primary-runtime]
|
||||
last_updated = "2026-08-03T08:16:52Z"
|
||||
source_type = "local"
|
||||
source = "/Users/jetpac/.cache/codex-runtimes/codex-primary-runtime/plugins/openai-primary-runtime"
|
||||
|
||||
@@ -1196,9 +1254,6 @@ enabled = true
|
||||
[plugins."browser@openai-bundled"]
|
||||
enabled = true
|
||||
|
||||
[plugins."sites@openai-bundled"]
|
||||
enabled = true
|
||||
|
||||
[plugins."chrome@openai-bundled"]
|
||||
enabled = true
|
||||
|
||||
@@ -1214,6 +1269,12 @@ enabled = true
|
||||
[plugins."visualize@openai-bundled"]
|
||||
enabled = true
|
||||
|
||||
[plugins."codex-app-tools@openai-bundled"]
|
||||
enabled = true
|
||||
|
||||
[plugins."unified-computer-use@openai-bundled"]
|
||||
enabled = true
|
||||
|
||||
[desktop]
|
||||
appearanceTheme = "system"
|
||||
composerEnterBehavior = "cmdIfMultiline"
|
||||
@@ -1236,9 +1297,7 @@ global = "iterm2"
|
||||
approval_mode = "approve"
|
||||
|
||||
[shell_environment_policy.set]
|
||||
BROWSER_USE_AVAILABLE_BACKENDS = "chrome,iab"
|
||||
NODE_REPL_TRUSTED_BROWSER_CLIENT_SHA256S = "028a14b6eaa6d98dac2aae00764345ab9f244801ed8493d42b9af3be5575006e,f204d340535055781952b10ed396de20b842f00a19e430852f7e121ad1ce91f6"
|
||||
NODE_REPL_TRUSTED_CODE_PATHS = "/Users/jetpac/.codex"
|
||||
|
||||
[hooks.state]
|
||||
|
||||
@@ -1524,7 +1583,7 @@ approval_mode = "approve"
|
||||
[mcp_servers.headroom]
|
||||
command = "headroom"
|
||||
args = ["mcp", "serve"]
|
||||
enabled = false
|
||||
enabled = true
|
||||
|
||||
[mcp_servers.serena]
|
||||
command = "uvx"
|
||||
@@ -1532,24 +1591,25 @@ args = ["--from", "git+https://github.com/oraios/serena", "serena", "start-mcp-s
|
||||
|
||||
[mcp_servers.node_repl]
|
||||
args = []
|
||||
command = "/Applications/Codex.app/Contents/Resources/cua_node/bin/node_repl"
|
||||
command = "/Applications/ChatGPT.app/Contents/Resources/cua_node/bin/node_repl"
|
||||
startup_timeout_sec = 120
|
||||
|
||||
[mcp_servers.node_repl.env]
|
||||
NODE_REPL_NATIVE_PIPE_CONNECT_TIMEOUT_MS = "1000"
|
||||
NODE_REPL_NODE_MODULE_DIRS = "/Applications/Codex.app/Contents/Resources/cua_node/lib/node_modules"
|
||||
NODE_REPL_NODE_PATH = "/Applications/Codex.app/Contents/Resources/cua_node/bin/node"
|
||||
NODE_REPL_TRUSTED_CODE_PATHS = "/Users/jetpac/.codex"
|
||||
NODE_REPL_NODE_MODULE_DIRS = "/Applications/ChatGPT.app/Contents/Resources/cua_node/lib/node_modules"
|
||||
NODE_REPL_NODE_PATH = "/Applications/ChatGPT.app/Contents/Resources/cua_node/bin/node"
|
||||
NODE_REPL_TRUSTED_CODE_PATHS = "/Users/jetpac/.codex:/Applications/ChatGPT.app/Contents/Resources/cua_node/lib/node_modules"
|
||||
CODEX_HOME = "/Users/jetpac/.codex"
|
||||
NODE_REPL_TRUSTED_BROWSER_CLIENT_SHA256S = "028a14b6eaa6d98dac2aae00764345ab9f244801ed8493d42b9af3be5575006e,f204d340535055781952b10ed396de20b842f00a19e430852f7e121ad1ce91f6"
|
||||
BROWSER_USE_AVAILABLE_BACKENDS = "chrome,iab"
|
||||
NODE_REPL_INSTRUCTIONS_USE_CASE_BROWSER = "Control the in-app browser in conjunction with the Browser Plugin."
|
||||
NODE_REPL_INSTRUCTIONS_USE_CASE_CHROME = "Control the Chrome browser in conjunction with the Chrome Plugin. Prefer this method of controlling Chrome over alternatives (such as Computer Use) unless the user explicitly mentions an alternative."
|
||||
NODE_REPL_INSTRUCTIONS_USE_CASE_COMPUTER_USE = "Control desktop apps on macOS through Computer Use."
|
||||
BROWSER_USE_TINYSKY_ENABLED = "1"
|
||||
NODE_REPL_INSTRUCTIONS_USE_CASE_BROWSER = ""
|
||||
NODE_REPL_INSTRUCTIONS_USE_CASE_CHROME = ""
|
||||
NODE_REPL_INSTRUCTIONS_USE_CASE_COMPUTER_USE = ""
|
||||
BROWSER_USE_CODEX_APP_BUILD_FLAVOR = "prod"
|
||||
BROWSER_USE_CODEX_APP_VERSION = "26.727.51351"
|
||||
BROWSER_USE_CODEX_APP_VERSION = "26.901.51231"
|
||||
NODE_REPL_TRUSTED_SERVICES = '{"browser":"/Users/jetpac/.codex/plugins/cache/openai-bundled/browser/26.901.51231/scripts/browser-service.mjs","sky":"@oai/sky/service"}'
|
||||
SKY_CUA_SERVICE_PATH = "/Users/jetpac/.codex/computer-use/Codex Computer Use.app"
|
||||
CODEX_CLI_PATH = "/Applications/Codex.app/Contents/Resources/codex"
|
||||
CODEX_CLI_PATH = "/Applications/ChatGPT.app/Contents/Resources/codex"
|
||||
|
||||
[mcp_servers.computer-use]
|
||||
command = "./Codex Computer Use.app/Contents/SharedSupport/SkyComputerUseClient.app/Contents/MacOS/SkyComputerUseClient"
|
||||
|
||||
@@ -19,6 +19,10 @@
|
||||
}
|
||||
],
|
||||
"to_if_alone": [{ "key_code": "escape" }],
|
||||
"conditions": [{
|
||||
"bundle_identifiers": ["^com\\.oracle\\.securedesktop$"],
|
||||
"type": "frontmost_application_unless"
|
||||
}],
|
||||
"type": "basic"
|
||||
},
|
||||
{
|
||||
@@ -36,6 +40,10 @@
|
||||
"modifiers": ["left_control"]
|
||||
}
|
||||
],
|
||||
"conditions": [{
|
||||
"bundle_identifiers": ["^com\\.oracle\\.securedesktop$"],
|
||||
"type": "frontmost_application_unless"
|
||||
}],
|
||||
"type": "basic"
|
||||
},
|
||||
{
|
||||
@@ -50,6 +58,10 @@
|
||||
"modifiers": ["left_control"]
|
||||
}
|
||||
],
|
||||
"conditions": [{
|
||||
"bundle_identifiers": ["^com\\.oracle\\.securedesktop$"],
|
||||
"type": "frontmost_application_unless"
|
||||
}],
|
||||
"type": "basic"
|
||||
},
|
||||
{
|
||||
@@ -64,6 +76,10 @@
|
||||
"modifiers": ["left_control", "left_command"]
|
||||
}
|
||||
],
|
||||
"conditions": [{
|
||||
"bundle_identifiers": ["^com\\.oracle\\.securedesktop$"],
|
||||
"type": "frontmost_application_unless"
|
||||
}],
|
||||
"type": "basic"
|
||||
}
|
||||
]
|
||||
@@ -2517,4 +2533,4 @@
|
||||
"virtual_hid_keyboard": { "keyboard_type_v2": "iso" }
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,28 @@
|
||||
foreground #bfbfbf
|
||||
background #282a2e
|
||||
selection_background #5c4c79
|
||||
url_color #29a1ae
|
||||
color0 #292b2d
|
||||
color8 #68717b
|
||||
color1 #ce527a
|
||||
color9 #ce527a
|
||||
color2 #2d9474
|
||||
color10 #84d82f
|
||||
color3 #bfa325
|
||||
color11 #edad0d
|
||||
color4 #4e97d6
|
||||
color12 #4c91cc
|
||||
color5 #bb6dc3
|
||||
color13 #bb6dc3
|
||||
color6 #299ba2
|
||||
color14 #299ba2
|
||||
color7 #e4e4e4
|
||||
color15 #f2f2f2
|
||||
|
||||
# START_AUTOGENERATED_TAB_STYLE
|
||||
# Feel free to update these colors manually and remove these comments.
|
||||
active_tab_foreground #eeeeee
|
||||
active_tab_background #5c4c79
|
||||
inactive_tab_foreground #bfbfbf
|
||||
inactive_tab_background #202225
|
||||
# END_AUTOGENERATED_TAB_STYLE
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,28 @@
|
||||
foreground #bfbfbf
|
||||
background #282a2e
|
||||
selection_background #5c4c79
|
||||
url_color #29a1ae
|
||||
color0 #292b2d
|
||||
color8 #68717b
|
||||
color1 #ce527a
|
||||
color9 #ce527a
|
||||
color2 #2d9474
|
||||
color10 #84d82f
|
||||
color3 #bfa325
|
||||
color11 #edad0d
|
||||
color4 #4e97d6
|
||||
color12 #4c91cc
|
||||
color5 #bb6dc3
|
||||
color13 #bb6dc3
|
||||
color6 #299ba2
|
||||
color14 #299ba2
|
||||
color7 #e4e4e4
|
||||
color15 #f2f2f2
|
||||
|
||||
# START_AUTOGENERATED_TAB_STYLE
|
||||
# Feel free to update these colors manually and remove these comments.
|
||||
active_tab_foreground #eeeeee
|
||||
active_tab_background #5c4c79
|
||||
inactive_tab_foreground #bfbfbf
|
||||
inactive_tab_background #202225
|
||||
# END_AUTOGENERATED_TAB_STYLE
|
||||
@@ -0,0 +1,28 @@
|
||||
foreground #bfbfbf
|
||||
background #282a2e
|
||||
selection_background #5c4c79
|
||||
url_color #29a1ae
|
||||
color0 #292b2d
|
||||
color8 #68717b
|
||||
color1 #ce527a
|
||||
color9 #ce527a
|
||||
color2 #2d9474
|
||||
color10 #84d82f
|
||||
color3 #bfa325
|
||||
color11 #edad0d
|
||||
color4 #4e97d6
|
||||
color12 #4c91cc
|
||||
color5 #bb6dc3
|
||||
color13 #bb6dc3
|
||||
color6 #299ba2
|
||||
color14 #299ba2
|
||||
color7 #e4e4e4
|
||||
color15 #f2f2f2
|
||||
|
||||
# START_AUTOGENERATED_TAB_STYLE
|
||||
# Feel free to update these colors manually and remove these comments.
|
||||
active_tab_foreground #eeeeee
|
||||
active_tab_background #5c4c79
|
||||
inactive_tab_foreground #bfbfbf
|
||||
inactive_tab_background #202225
|
||||
# END_AUTOGENERATED_TAB_STYLE
|
||||
+12
-1
@@ -1,3 +1,4 @@
|
||||
Include config.solaris-domain
|
||||
Include config-scm
|
||||
Include ssh_configs/config
|
||||
Include osd_configs/config
|
||||
@@ -11,7 +12,6 @@ Host *
|
||||
# HostkeyAlgorithms +ssh-rsa
|
||||
# PubkeyAcceptedAlgorithms +ssh-rsa
|
||||
|
||||
Include config.solaris-domain
|
||||
|
||||
Host bitbucket.oci.oraclecorp.com
|
||||
HostName bitbucket.oci.oraclecorp.com
|
||||
@@ -21,6 +21,17 @@ Host bitbucket.oci.oraclecorp.com
|
||||
AddKeysToAgent yes
|
||||
UseKeychain yes
|
||||
|
||||
Host devon-testing
|
||||
HostName 100.99.34.177
|
||||
User opc
|
||||
IdentityFile ~/.ssh/id_rsa
|
||||
IdentitiesOnly yes
|
||||
|
||||
# Virtual admin instance in Frankfurt
|
||||
Host admin
|
||||
HostName 100.99.34.143
|
||||
|
||||
|
||||
Host s11sru-x01 s11sru-x01.us.oracle.com
|
||||
KexAlgorithms +diffie-hellman-group1-sha1
|
||||
|
||||
|
||||
@@ -20,6 +20,11 @@ Host 192.168.2.*
|
||||
IdentitiesOnly yes
|
||||
|
||||
|
||||
Host akidr.oraclecorp.com
|
||||
User opc
|
||||
IdentitiesOnly yes
|
||||
IdentityFile /Users/jetpac/.ssh/akidr.oraclecorp.com.key
|
||||
|
||||
|
||||
Host osd-fra
|
||||
User desktopuser
|
||||
@@ -170,6 +175,7 @@ Host adam-test
|
||||
Host nori sfzfs-nori.commonsub.zsphx.oraclevcn.com
|
||||
Hostname sfzfs-nori.commonsub.zsphx.oraclevcn.com
|
||||
User opc
|
||||
IdentitiesOnly yes
|
||||
IdentityFile ~/.ssh/nori
|
||||
|
||||
|
||||
|
||||
@@ -106,8 +106,8 @@ alias speech_to_text="$HOME/Downloads/whisper.cpp/convert_video_to_txt.sh"
|
||||
alias scm-ssh='/Users/jetpac/.ssh/scm-script.sh'
|
||||
|
||||
if [[ "$(hostname)" == "speccy" ]]; then
|
||||
export TERM=xterm-24bit
|
||||
alias ssh='TERM=xterm-256color ssh'
|
||||
# export TERM=xterm-24bit
|
||||
# alias ssh='TERM=xterm-256color ssh'
|
||||
alias vi=te
|
||||
alias vim=te
|
||||
fi
|
||||
|
||||
@@ -0,0 +1,62 @@
|
||||
## Engineering Principles
|
||||
|
||||
Apply YAGNI, KISS, and DRY whenever practical:
|
||||
|
||||
- **YAGNI (You Aren't Gonna Need It):** Implement current requirements. Avoid
|
||||
speculative features, abstractions, configuration, and dependencies.
|
||||
- **KISS (Keep It Simple):** Choose the simplest clear, maintainable solution
|
||||
that meets the requirements. Avoid unnecessary complexity and indirection.
|
||||
- **DRY (Don't Repeat Yourself):** Reuse existing code and centralize shared
|
||||
logic and knowledge when appropriate. Avoid premature abstractions that
|
||||
couple unrelated behavior merely because it looks similar.
|
||||
- **Modern industry standards:** Follow current, widely accepted standards and
|
||||
idiomatic practices for the language, framework, security, and accessibility
|
||||
relevant to the task. Respect supported runtimes and project constraints;
|
||||
verify evolving guidance when needed and avoid adopting novelty for its own
|
||||
sake.
|
||||
|
||||
Use judgment when these principles conflict, and briefly explain material
|
||||
tradeoffs or exceptions.
|
||||
|
||||
<!-- headroom:rtk-instructions -->
|
||||
# RTK (Rust Token Killer) - Token-Optimized Commands
|
||||
|
||||
When running shell commands, **always prefix with `rtk`**. This reduces context
|
||||
usage by 60-90% with zero behavior change. If rtk has no filter for a command,
|
||||
it passes through unchanged — so it is always safe to use.
|
||||
|
||||
## Key Commands
|
||||
```bash
|
||||
# Git (59-80% savings)
|
||||
rtk git status rtk git diff rtk git log
|
||||
|
||||
# Files & Search (60-75% savings)
|
||||
rtk ls <path> rtk read <file> rtk grep <pattern>
|
||||
rtk find <pattern> rtk diff <file>
|
||||
|
||||
# Test (90-99% savings) — shows failures only
|
||||
rtk pytest tests/ rtk cargo test rtk test <cmd>
|
||||
|
||||
# Build & Lint (80-90% savings) — shows errors only
|
||||
rtk tsc rtk lint rtk cargo build
|
||||
rtk prettier --check rtk mypy rtk ruff check
|
||||
|
||||
# Analysis (70-90% savings)
|
||||
rtk err <cmd> rtk log <file> rtk json <file>
|
||||
rtk summary <cmd> rtk deps rtk env
|
||||
|
||||
# GitHub (26-87% savings)
|
||||
rtk gh pr view <n> rtk gh run list rtk gh issue list
|
||||
|
||||
# Infrastructure (85% savings)
|
||||
rtk docker ps rtk kubectl get rtk docker logs <c>
|
||||
|
||||
# Package managers (70-90% savings)
|
||||
rtk pip list rtk pnpm install rtk npm run <script>
|
||||
```
|
||||
|
||||
## Rules
|
||||
- In command chains, prefix each segment: `rtk git add . && rtk git commit -m "msg"`
|
||||
- For debugging, use raw command without rtk prefix
|
||||
- `rtk proxy <cmd>` runs command without filtering but tracks usage
|
||||
<!-- /headroom:rtk-instructions -->
|
||||
@@ -245,8 +245,49 @@ codex_auth_write_gateway_op_token() {
|
||||
codex_auth_log "MCP Gateway auth preflight: wrote fresh operator token to ${token_file}."
|
||||
}
|
||||
|
||||
codex_auth_reuse_gateway_op_token() {
|
||||
local cached_token
|
||||
|
||||
[[ -r "${MCPGW_OP_TOKEN_FILE}" ]] || return 1
|
||||
# Inspect expiry locally; the gateway remains responsible for JWT verification.
|
||||
# Keep the token out of command arguments and diagnostic output.
|
||||
if ! cached_token="$(python3 - "${MCPGW_OP_TOKEN_FILE}" <<'PY'
|
||||
import base64
|
||||
import json
|
||||
import math
|
||||
import sys
|
||||
import time
|
||||
from pathlib import Path
|
||||
|
||||
try:
|
||||
token = Path(sys.argv[1]).read_text().strip()
|
||||
header, payload, signature = token.split(".")
|
||||
if not header or not payload or not signature:
|
||||
raise ValueError("Incomplete JWT")
|
||||
claims = json.loads(base64.b64decode(
|
||||
payload + "=" * (-len(payload) % 4), altchars=b"-_", validate=True
|
||||
))
|
||||
expiry = claims["exp"]
|
||||
valid = (type(expiry) in (int, float) and math.isfinite(expiry)
|
||||
and expiry > time.time() + 300)
|
||||
except (OSError, ValueError, KeyError, TypeError):
|
||||
valid = False
|
||||
if not valid:
|
||||
sys.exit(1)
|
||||
print(token)
|
||||
PY
|
||||
)"
|
||||
then
|
||||
return 1
|
||||
fi
|
||||
|
||||
export OP_TOKEN="${cached_token}"
|
||||
export OPERATOR_ACCESS_TOKEN="${cached_token}"
|
||||
codex_auth_log "MCP Gateway auth preflight: reusing cached operator token (more than 5 minutes remaining)."
|
||||
}
|
||||
|
||||
codex_auth_refresh_gateway_auth() {
|
||||
local mcpgw_bin op_token_refreshed=0
|
||||
local mcpgw_bin op_token_ready=0
|
||||
mcpgw_bin="$(command -v mcpgw 2>/dev/null || true)"
|
||||
|
||||
if [[ -n "${mcpgw_bin}" ]]; then
|
||||
@@ -255,8 +296,10 @@ codex_auth_refresh_gateway_auth() {
|
||||
codex_auth_log "Warning: mcpgw not found on PATH; skipping MCP Gateway auth refresh."
|
||||
fi
|
||||
|
||||
if codex_auth_prepare_codex_auth && codex_auth_write_gateway_op_token; then
|
||||
op_token_refreshed=1
|
||||
if codex_auth_reuse_gateway_op_token; then
|
||||
op_token_ready=1
|
||||
elif codex_auth_prepare_codex_auth && codex_auth_write_gateway_op_token; then
|
||||
op_token_ready=1
|
||||
else
|
||||
codex_auth_log "Warning: could not refresh OP token; continuing with existing MCP Gateway token state."
|
||||
fi
|
||||
@@ -265,7 +308,7 @@ codex_auth_refresh_gateway_auth() {
|
||||
return 0
|
||||
fi
|
||||
|
||||
if [[ "${op_token_refreshed}" != "1" ]]; then
|
||||
if [[ "${op_token_ready}" != "1" ]]; then
|
||||
codex_auth_log "MCP Gateway auth preflight: skipping token-dependent checks because OP token refresh failed."
|
||||
return 0
|
||||
fi
|
||||
|
||||
Executable
+3
@@ -0,0 +1,3 @@
|
||||
#!/bin/sh
|
||||
export HEADROOM_TELEMETRY=off
|
||||
exec conda run --no-capture-output -n headroom headroom "$@"
|
||||
Reference in New Issue
Block a user