fix: make OpenAI Codex (ChatGPT subscription) sign-in fail loudly instead of silently dead-ending (#13537)
* fix: make OpenAI Codex sign-in fail loudly instead of silently dead-ending When callback port 1455 is already in use (e.g. by the Codex CLI or a previous pending sign-in), startLocalOAuthServer returns a no-op server and loginOpenAICodex would open the browser anyway, then dead-end: the callback could never be received, and in the VS Code extension the user just saw nothing happen after clicking 'Sign in to OpenAI Codex'. - loginOpenAICodex now fails fast with an actionable 'port in use' error before opening the browser, unless the host provides manual code entry (the CLI's paste fallback keeps working) - surface OAuth redirect errors (e.g. access_denied) instead of collapsing them into 'Missing authorization code' - the extension dedupes concurrent sign-in clicks: a re-click re-opens the auth page of the pending flow instead of spawning a second flow that would collide with our own callback server - browser-open failures now show an error message with the URL to open manually instead of only logging - abandoned-flow timeouts no longer surface a confusing 'Missing authorization code' toast Co-authored-by: Saoud Rizwan <saoudrizwan@users.noreply.github.com> * refactor: drop host-side codex login dedupe, keep flow identical to CLI The SDK owns the failure handling now (fail-fast on an unbindable callback port), so the extension keeps the exact same simple loginOpenAICodex call the CLI uses. A second click while a flow is pending gets the SDK's clear port-in-use error, same as running 'cline auth openai-codex' twice would. Keep only the CLI-parallel onOpenUrlError surfacing (the CLI prints 'open the URL above manually'; the extension's equivalent is an error toast with the URL). Co-authored-by: Saoud Rizwan <saoudrizwan@users.noreply.github.com> * test(e2e): cover Codex sign-in callback-port failure and redirect errors Two driven-VS Code tests for the OpenAI Codex (ChatGPT subscription) sign-in flow: - with port 1455 occupied on both loopback families, clicking the sign-in button surfaces the fail-fast port-in-use toast - with the port free, the callback server binds and an OAuth redirect error (access_denied) propagates to a visible error toast The second test opens a real browser tab to the OpenAI auth page as a side effect of the genuine sign-in click. --------- Co-authored-by: Saoud Rizwan <saoudrizwan@users.noreply.github.com> Co-authored-by: Mikołaj Kondratek <19799111+mkondratek@users.noreply.github.com>
S
Saoud Rizwan committed
8eca7575b4a8a8eefb9dc05d070dbd048fc34143
Parent: 006de71
Committed by GitHub <noreply@github.com>
on 8/27/2026, 8:10:35 PM