Skip to content

Expose effective login methods in config requirements - #45495

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/56c0767a74143e793aac2ac165d0cbe98a09469b
Sep 14, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/56c0767a74143e793aac2ac165d0cbe98a09469b

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Expose effective login methods in config requirements

Why

Configuration requirements did not report which login methods the running app server permits after applying managed policy, forced login settings, and workspace restrictions.

What changed

  • Add allowedLoginMethods to configRequirements/read, using the running authentication manager's effective policy rather than newly read authentication settings.
  • Return requirements when login methods are restricted even without managed requirements, while preserving requirements: null for the unrestricted default.
  • Update protocol schemas and generated TypeScript and Python types. An empty list permits no login method; older servers may omit the field.

Testing

Add coverage for managed and forced login restrictions, workspace intersections, policy reporting after requirements files change, invalid login methods, and API-only Amazon Bedrock without ChatGPT requests. Extend tests for conflicting authentication requirements and cloud policy precedence.

## Why

Configuration requirements did not report which login methods the running app server permits after applying managed policy, forced login settings, and workspace restrictions.

## What changed

- Add `allowedLoginMethods` to `configRequirements/read`, using the running authentication manager's effective policy rather than newly read authentication settings.
- Return requirements when login methods are restricted even without managed requirements, while preserving `requirements: null` for the unrestricted default.
- Update protocol schemas and generated TypeScript and Python types. An empty list permits no login method; older servers may omit the field.

## Testing

Add coverage for managed and forced login restrictions, workspace intersections, policy reporting after requirements files change, invalid login methods, and API-only Amazon Bedrock without ChatGPT requests. Extend tests for conflicting authentication requirements and cloud policy precedence.

GitOrigin-RevId: 56c0767a74143e793aac2ac165d0cbe98a09469b
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/56c0767a74143e793aac2ac165d0cbe98a09469b branch from ecbc33a to a20092a Compare September 14, 2026 19:11
@copyberry
copyberry Bot merged commit a20092a into main Sep 14, 2026
1 check passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/56c0767a74143e793aac2ac165d0cbe98a09469b branch September 14, 2026 19:11
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 14, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant