Skip to content

Add guided admin key setup and verification - #387

Draft
saioai wants to merge 17 commits into
mainfrom
codex/admin-setup-public-20261008
Draft

saioai wants to merge 17 commits into
mainfrom
codex/admin-setup-public-20261008

Conversation

@saioai

@saioai saioai commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Admin commands currently fail without explaining that they need an admin key.
This adds clear guidance and openai setup admin, which hides key entry and verifies access automatically.

What changes

  • Explain admin-key requirements after validating required command inputs.
  • Show the key-creation link before hidden entry.
  • Verify access with one read-only project-list request, with a 15-second timeout and no retries or redirects.
  • Keep the key in that process. Setup does not save credentials or authenticate later commands.
  • Preserve cancellation and restore terminal input after entry.
  • Cover standard and mTLS OpenAI hosts while preserving explicit authentication and custom-endpoint overrides.
  • Escape the displayed destination without changing the request URL.
  • Retain offline setup instructions and existing machine-readable errors.

Commands

openai setup admin         # Hidden key entry and automatic verification.
openai setup admin --help  # Interactive command details.
openai help setup admin    # Offline key creation and manual setup guide.

Interactive setup requires terminal input and diagnostic output in text mode.
Debug logging and structured output stop before prompting.
The destination follows --base-url or OPENAI_BASE_URL.
HTTPS is required except for loopback servers.
The entered key replaces Authorization; other configured headers and mTLS remain active.
An empty project list also verifies access successfully.

Code

pkg/custom owns credential checks, setup orchestration, hidden input, and safe errors.
The Windows factory uses a console-record reader with cancellable waits and joined cleanup.
macOS and Linux retain the existing reader with platform input cleanup.
The parser, signal handling, and verification request remain shared.

Canonical metadata survives command cloning.
Request setup checks credentials after required-input validation and before file expansion.
No new package, dependency, generated-command change, main.go change, or budget increase is included.

Tested

Candidate 8487ddf includes main 390a9c3 and preserves Models, Images, and Shell behavior.
After main alignment, all 458 affected product-test entries passed without failures or skips.
Separate presenter checks preserved Admin, download, and save-receipt diagnostics around context errors.
The 21 native macOS key-entry cases passed on 15e8c66; their exact reader source remains unchanged.
All 14 public-command cases passed on the aligned binary in the serialized macOS run.
They cover typed/pasted input, cancellation, invalid input, redirected output, rejected modes, and terminal restoration.
Successful verification issued one loopback GET. Tests used synthetic keys and left home files unchanged.

Both Windows test packages compiled, and Windows vet passed.
Local validation used Go 1.27.0 on macOS arm64; compilation does not establish native Windows behavior.
On head 8487ddf, Windows CI passed 35 production sessions and 37 distinct input/error checks.
On head 8487ddf, Linux CI passed the full test suite, including the selected terminal test.
Its quiet package logs do not print individual case names.

Independent exact-source review verified all 950 files in the aligned snapshot.
Head 8487ddf passed CI, CodeQL, build artifacts, all 9 vulnerability targets, and the 21/1000 budget gate.
CI tested the same source tree as the reviewed candidate. Help checks passed on macOS, Linux, and Windows.
No workflow, scanner, or budget gate changed.
Windows Terminal application behavior and live API verification remain untested.

Demo

Actual binaries on macOS arm64, comparing main d32b3ae with ce129ba.
The recording uses a synthetic key and loopback API. No live key is created.
The follow-up preserves this setup output; its validation and cancellation corrections have separate regression coverage.

Admin setup before and after

Before:

Before: no interactive setup

After:

After: hidden input and automatic verification

Recording recipe · Synthetic fixture

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Castiron custom code

Evaluated main: 390a9c3d68e93f7348509ffec169bb5ab38d68cc.

✅ No new custom-code files detected.

2 mixed files remain; 0 existing customizations changed.

Compared 390a9c3d68e9 → 8487ddf7f92c. Generated baselines verified.

2 existing customizations unchanged
  • pkg/cmd/adminorganizationcertificate.go
  • pkg/cmd/audiovoice.go

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 37896656145 --repo openai/openai-cli \
  --name castiron-custom-code-37896656145-1 --dir /tmp/castiron-custom-code-37896656145-1
git apply --stat /tmp/castiron-custom-code-37896656145-1/custom-code.patch
cat /tmp/castiron-custom-code-37896656145-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin 390a9c3d68e93f7348509ffec169bb5ab38d68cc 8487ddf7f92c8a49ac06fc3e86f5e2490d79d0d1
python3 scripts/castiron/custom_code_report.py report \
  --base 390a9c3d68e93f7348509ffec169bb5ab38d68cc \
  --head 8487ddf7f92c8a49ac06fc3e86f5e2490d79d0d1 --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-8487ddf7f92c
cat /tmp/castiron-custom-code-8487ddf7f92c/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

@saioai

saioai commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

Please review commit ce129ba36684bb4f523b44b2778b633a544fe69c against this PR's current base. Check public-command behavior, preserved input/output contracts, errors, and cancellation. Distinguish code defects from the documented validation limits.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T18:17:41.858595Z 3c60f69 Manual request
🔒 Security Review ✅ Completed 2026-10-08T18:15:01.559448Z 3c60f69 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ce129ba366

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread pkg/custom/admin_setup_interactive.go Outdated
Comment thread pkg/custom/admin_credentials.go Outdated
Comment thread pkg/custom/admin_credentials.go Outdated
@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: ce129ba366

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@saioai

saioai commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

Please review the functional correction in 00be8a07529159e9d713cccdd496a6a53b73c2de, including code and security checks.

It addresses the three findings from ce129ba36684bb4f523b44b2778b633a544fe69c.
Required and piped input validation now precedes credential checks.
Checkpoint permissions and positional routes receive the same admin-key guidance.
Cancellation retains standard context errors while keeping private causes hidden.
The PR base remains unchanged.

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: 00be8a0752

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🚀

Reviewed commit: 00be8a0752

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

…min-setup-public-20261008

# Conflicts:
#	pkg/custom/help.go
@saioai

saioai commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

Please review code and security for Help-aligned head 3c60f6970a34a5451bd900d136de94f5018c4b63 against main 6fcc478086507571286727084a7d7b162a37ab51.

This local merge preserves the reviewed Admin correction from 00be8a and main's complete Help behavior.
The Help conflict retains the Admin manual guide after main's configuration.
Admin validation tests now require main's exact command-specific error guidance.
All Admin runtime files remain unchanged from the reviewed correction.
Focused integration checks, the exact binary build, vet, and the trusted budget check passed.
Earlier hosted reviews remain attributed to 00be8a.

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: 3c60f6970a

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3c60f6970a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread pkg/custom/admin_credentials.go Outdated
Comment on lines +67 to +68
if client, ok := command.Root().Metadata[mtlsHTTPClientMetadata].(*http.Client); ok && client != nil {
return nil

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep the admin-key preflight active for mTLS

When an admin command targets the standard API with mTLS files configured but no OPENAI_ADMIN_KEY, configureMTLS stores a non-nil client and this branch treats that client as sufficient authentication. mTLS only authenticates API-key requests (README.md:211-223) and does not add an Authorization header, so the request proceeds without an admin key and returns a remote authentication error instead of the new setup guidance. Keep the key check active for mTLS clients, including the documented mtls.api.openai.com endpoint that usesStandardAdminService currently excludes, and cover that configuration with a focused regression test.

AGENTS.md reference: AGENTS.md:L76-L81

Useful? React with 👍 / 👎.

}
ctx, stop := adminSetupSignalContext(ctx)
defer stop()
if _, err := fmt.Fprintf(os.Stderr, "Admin key verification\n\nNeed a key? Open:\n https://platform.openai.com/settings/organization/admin-keys\nSelect your organization.\nCreate an admin key.\nCopy the key into the hidden prompt below.\nOnly organization owners can create admin keys.\nIf you are not an owner, ask an owner to run the operation without sharing their key.\n\nDestination: %s\nThe key stays in this process. Ctrl+C cancels.\n\n", destination); err != nil {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Canonicalize the displayed verification host

When --base-url or OPENAI_BASE_URL contains a valid IDN hostname, such as one using a Cyrillic а in аpi.openai.com, url.Parse preserves the Unicode spelling while net/http converts it to punycode for the request. This prints the visually confusable spelling immediately before asking for the admin key, so a malicious inherited configuration can make an attacker-controlled endpoint look like the trusted API and receive the pasted key. Display a canonical ASCII/punycode host and terminal-escape it before prompting.

AGENTS.md reference: AGENTS.md:L51-L55

Useful? React with 👍 / 👎.

Comment on lines +63 to +66
reader.Cancel()
// Join the reader before restoring echo, clearing any unconsumed input.
for chunk := range chunks {
clear(chunk)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Flush terminal input before returning to the shell

On a terminal that does not emit bracketed-paste markers, or when a pasted suffix remains beyond the current 4096-byte read, the first CR/LF makes collectAdminSetupKey return while later bytes can remain in the terminal's OS input queue. This cleanup only drains chunks already forwarded by the goroutine; it does not flush that queue before restoring canonical mode, so remaining pasted lines are handed to the parent shell after the CLI exits and can execute as commands. Flush pending terminal input before restoring and add a PTY regression using an unmarked multiline paste split across reads.

AGENTS.md reference: AGENTS.md:L51-L55

Useful? React with 👍 / 👎.

go readAdminSetupKeyBytes(readCtx, reader, chunks)
defer func() {
cancel()
reader.Cancel()

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Handle failed Windows reader cancellation

On Windows Terminal, the ultraviolet cancel reader explicitly permits Cancel() to return false when its console read cannot be interrupted. Ignoring that result and then ranging until chunks closes waits forever for the still-blocked reader goroutine, so parent-context cancellation or a signal can leave setup hung in raw/no-echo mode instead of restoring the terminal. Handle the failed-cancel path without an unbounded join and cover cancellation in a native Windows console test.

AGENTS.md reference: AGENTS.md:L51-L55

Useful? React with 👍 / 👎.

@jbeckwith-oai jbeckwith-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed credential precedence and validation order, cloned admin routes, endpoint/mTLS preservation, hidden input, cancellation, verification, and error presentation. No blocking findings; the previously reported issues appear addressed.

On the exact head, focused TestAdmin and public TestMainAdmin tests, go vet ./..., and changed-file gofmt checks pass. A temporary credential-acceptance mutation was caught by the tests, and the restored tests passed. Hosted checks pass. Native Windows behavior was reviewed statically, not executed; no live API calls were made.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants