feat(codex-app-gateway): real buildConfig — fetch connected executors + mint per-thread cap tokens - #81
Open
imryao wants to merge 1 commit into
Open
feat(codex-app-gateway): real buildConfig — fetch connected executors + mint per-thread cap tokens#81imryao wants to merge 1 commit into
imryao wants to merge 1 commit into
Conversation
… + mint per-thread cap tokens Replaces the documented Phase-1 stub in NewServer's buildConfig with a real implementation that closes the last gap in the codex-gateway end-to-end chain: spawned codex app-server subprocesses now actually receive [mcp_servers.exe_*] entries, so the LLM sees mcp__exe_*__shell tools. - New internal/codexappgateway/captoken: HMAC cap-token mint matching the format codex-exec-gateway's auth.go verifies. Cross-service round-trip test imports VerifyCapabilityToken to lock the contract. - New internal/codexappgateway/execgwclient: GET /api/exec-gateway/connected HTTP client with shared-secret bearer auth. - buildConfig now fetches executors per (workspace, thread), mints one single-exe-id token per executor (24h exp, threadID as audit key), and populates ConfigInput.Executors. ConfigBuilder closure now takes ctx. - Integration test stands up a fake exec-gateway, exercises buildConfig end-to-end, asserts tokens verify and config.toml renders the expected [mcp_servers.exe_*] entries. After this commit, the chain is complete: TUI → codex-app-gateway (auth) → spawn codex app-server (with real mcp_servers config) → spawn env-mcp child per executor → ws bridge to codex-exec-gateway → real codex-exec on user's laptop. Follow-up: invoke /api/exec-gateway/revoke-turn on subprocess shutdown to invalidate the cap token before its EXP. Currently relies on EXP only. Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes the last gap in the codex-gateway end-to-end chain. Replaces the documented Phase-1 stub in `NewServer`'s `buildConfig` with a real implementation. Spawned `codex app-server` subprocesses now actually receive `[mcp_servers.exe_]` entries, so the LLM sees `mcp__exe___shell` tools.
What's in here
End-to-end chain after this PR
```
TUI codex --remote
→ codex-app-gateway (HMAC auth)
→ spawn codex app-server subprocess (with REAL [mcp_servers.exe_*] config) ← this PR
→ spawn env-mcp child per executor (PR #78)
→ ws bridge to codex-exec-gateway (PR #80)
→ real codex-exec on user's laptop
```
Test Plan
Spec / Plan
Follow-ups (deferred, not blocking)