Files
OmniRoute/open-sse/executors/chatgpt-web-codex/credentials.ts
Jan Leon a99c795a67 Add native ChatGPT Web provider for Codex clients (#8949)
* Bypass proxy compaction for native Codex context

* Add native ChatGPT Web provider pipeline

* Add managed browser and tunnel deployment

* Add ChatGPT Web setup and doctor UI

* Document and test ChatGPT Web integration

* fix(security): register chatgpt-web-codex-doctor in LOCAL_ONLY_API_PATTERNS

The diagnostic route under /api/providers/{id}/chatgpt-web-codex-doctor
was not registered in the spawn-capable route guard. Adding it for
parity with the existing /login pattern.

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>

* fix(providers): route chatgpt-web-codex admin routes through a service boundary

The provider CRUD/doctor routes imported chatgpt-web-codex helpers
(finalizeValidatedChatGptWebCodexSecrets, encode/decodeChatGptWebCodexSecrets,
getChatGptWebCodexDoctorStatus) directly from open-sse/executors/**, which
no-restricted-imports (EXECUTOR_IMPORT_RESTRICTION) forbids for src/app/**
files — executor implementations must stay behind an open-sse handler or
service boundary.

Add open-sse/services/chatgptWebCodexAdmin.ts as a thin re-export boundary
(mirroring the existing tokenRefresh.ts re-export pattern) and import from
there instead. No behavior change.

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>

---------

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
2026-08-11 09:53:39 -03:00

59 lines
2.0 KiB
TypeScript

export type ChatGptWebCodexSecrets = {
cookie?: string;
storageState?: Record<string, unknown>;
runtimeKey?: string;
};
const VERSION = 2;
function normalizedCookie(value: string): string {
return value.trim().replace(/^cookie\s*:\s*/i, "");
}
export function encodeChatGptWebCodexSecrets(secrets: ChatGptWebCodexSecrets): string {
const cookie = secrets.cookie ? normalizedCookie(secrets.cookie) : "";
const storageState = secrets.storageState;
if (!cookie && (!storageState || typeof storageState !== "object")) {
throw new Error("ChatGPT Cookie or verified browser storage state is required");
}
return JSON.stringify({
version: VERSION,
...(storageState ? { storageState } : { cookie }),
...(secrets.runtimeKey?.trim() ? { runtimeKey: secrets.runtimeKey.trim() } : {}),
});
}
export function decodeChatGptWebCodexSecrets(value: string): ChatGptWebCodexSecrets {
const trimmed = value.trim();
if (!trimmed) throw new Error("ChatGPT Web (Codex) credentials are missing");
try {
const parsed = JSON.parse(trimmed) as Record<string, unknown>;
if (
parsed.version === VERSION &&
parsed.storageState &&
typeof parsed.storageState === "object"
) {
return {
storageState: parsed.storageState as Record<string, unknown>,
...(typeof parsed.runtimeKey === "string" && parsed.runtimeKey.trim()
? { runtimeKey: parsed.runtimeKey.trim() }
: {}),
};
}
if ((parsed.version === VERSION || parsed.version === 1) && typeof parsed.cookie === "string") {
const cookie = normalizedCookie(parsed.cookie);
if (!cookie) throw new Error("ChatGPT Cookie is missing");
return {
cookie,
...(typeof parsed.runtimeKey === "string" && parsed.runtimeKey.trim()
? { runtimeKey: parsed.runtimeKey.trim() }
: {}),
};
}
} catch (error) {
if (error instanceof SyntaxError) return { cookie: normalizedCookie(trimmed) };
throw error;
}
return { cookie: normalizedCookie(trimmed) };
}