Repository navigation
Read the console through Core's /core/v1 routes and manage executor credentials - #127
Merged
SaladDay merged 11 commits intoSep 25, 2026
Merged
Conversation
Rotating a key_id never issued for the environment returns 404, key IDs must be lowercase non-nil canonical UUIDs, and not-found responses use Core's not_found_error code.
Core refuses issue and rotate on an archived project with 409 project_archived while list and revoke still work. The fixture returns that 409, and the Session page hides Issue and Rotate with a note; a write that meets project_archived shows the same note as its error and rereads the projects instead of entering rotate recovery.
A kept key ID from an issuance with an unknown outcome is no longer sent again once it is listed, and a successful rotation or revocation of it forgets it, so the next Issue starts a new credential instead of offering to rotate one that was just rotated or revoked. An existing key ID (409) opens rotation only after a fresh read shows it active in an active project; otherwise the issuance is reported as rejected. Dismissing the one-time credential dialog now keeps the credential on the page until Done, as the API-key flow does. The list's date column is "Created", and the empty state no longer repeats the Issue button.
Core accepts the self_hosted environment of any existing Session in the project and returns 404 otherwise; its only conflicts are project_archived and executor_credential_exists, and rotation restores a revoked key, which the console hides by choice. Record the archived-project view, the recovery rules and the Session page's credential management.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Web half of the Core/Web boundary paths pair (P2b). Targets the integration branch
codex/core-web-boundary; the backend merges the pair to main after its full gate.What changes
/core/v1. The console uses Core'sCoreProjectReader,AdminClient,SandboxAdminClientandCoreMetricsClienton the new routes (no/adminsegment;/core/v1/metrics;/core/v1/sandbox/runtime-observations). The web no longer usesOpenAIAgentsClient; the Vite dev proxy has a single/core/v1entry. The project reader is checked withsatisfies CoreProjectReaderagainst the shared client.key_id, issued, revoked), issue, rotate and revoke.key_id, rereads the list and recovers through rotation.409 executor_credential_existsenters the same recovery.409 project_archived); list and revoke stay.key_idreturns 404.key_idmust be a lowercase, non-nil UUID (400). An archived project gets 409project_archived.error.typeis derived the waywriteErrordoes./core/v1/*in place of the old route allowlist. Links now point tocore_routes.go,server.goandauth.go.packages/agents-clientis untouched: it is byte-identical to the base branch.Verification
go test ./services/core-console/... ./contracts/agents-api/.../core/v1path exists incontracts/agents-api/core.openapi.yaml. The one extra,GET /core/v1/projects/{id}, predates this branch and the web doesn't call it.Need help on this PR? Tag
@codesmithwith what you need. Autofix is disabled.