Skip to content

Read the console through Core's /core/v1 routes and manage executor credentials - #127

Merged
SaladDay merged 11 commits into
codex/core-web-boundaryfrom
codex/web-executor-credentials
Sep 25, 2026
Merged

SaladDay merged 11 commits into
codex/core-web-boundaryfrom
codex/web-executor-credentials

Conversation

@SaladDay

@SaladDay SaladDay commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Web half of the Core/Web boundary paths pair (P2b). Targets the integration branch codex/core-web-boundary; the backend merges the pair to main after its full gate.

What changes

  • Web reads everything through /core/v1. The console uses Core's CoreProjectReader, AdminClient, SandboxAdminClient and CoreMetricsClient on the new routes (no /admin segment; /core/v1/metrics; /core/v1/sandbox/runtime-observations). The web no longer uses OpenAIAgentsClient; the Vite dev proxy has a single /core/v1 entry. The project reader is checked with satisfies CoreProjectReader against the shared client.
  • Executor credentials on a self-hosted Session. List (key_id, issued, revoked), issue, rotate and revoke.
    • The secret is shown once and is never kept in browser storage.
    • An issuance with an unknown outcome keeps its key_id, rereads the list and recovers through rotation.
    • 409 executor_credential_exists enters the same recovery.
    • On an archived project, issue and rotate are hidden (Core: 409 project_archived); list and revoke stay.
  • e2e fixture matches Core. Rotating an unknown key_id returns 404. key_id must be a lowercase, non-nil UUID (400). An archived project gets 409 project_archived. error.type is derived the way writeError does.
  • docs/web describe Core key login and prefix forwarding of /core/v1/* in place of the old route allowlist. Links now point to core_routes.go, server.go and auth.go.

packages/agents-client is untouched: it is byte-identical to the base branch.

Verification

  • agents-client typecheck, tests 588/588
  • apps/web typecheck, tests 332/332, build
  • Web e2e (full suite) 16/16
  • go test ./services/core-console/... ./contracts/agents-api/...
  • Every fixture /core/v1 path exists in contracts/agents-api/core.openapi.yaml. The one extra, GET /core/v1/projects/{id}, predates this branch and the web doesn't call it.
  • Preview mocks: every console page, the executor section and the fresh-install flow render with no failed requests.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith with what you need. Autofix is disabled.

Rotating a key_id never issued for the environment returns 404, key IDs must be lowercase non-nil canonical UUIDs, and not-found responses use Core's not_found_error code.
Core refuses issue and rotate on an archived project with 409 project_archived while list and revoke still work. The fixture returns that 409, and the Session page hides Issue and Rotate with a note; a write that meets project_archived shows the same note as its error and rereads the projects instead of entering rotate recovery.
A kept key ID from an issuance with an unknown outcome is no longer sent
again once it is listed, and a successful rotation or revocation of it
forgets it, so the next Issue starts a new credential instead of offering
to rotate one that was just rotated or revoked. An existing key ID (409)
opens rotation only after a fresh read shows it active in an active
project; otherwise the issuance is reported as rejected.

Dismissing the one-time credential dialog now keeps the credential on the
page until Done, as the API-key flow does. The list's date column is
"Created", and the empty state no longer repeats the Issue button.
Core accepts the self_hosted environment of any existing Session in the project and returns 404 otherwise; its only conflicts are project_archived and executor_credential_exists, and rotation restores a revoked key, which the console hides by choice. Record the archived-project view, the recovery rules and the Session page's credential management.
@SaladDay
SaladDay merged commit f9b145c into codex/core-web-boundary Sep 25, 2026
2 checks passed
@SaladDay
SaladDay deleted the codex/web-executor-credentials branch October 10, 2026 05:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant