app
Codex
Public Made by Adomby adom
Codex in Adom Hydrogen: ecosystem setup, dock dashboard and live engineering demos.
← Commit history
Add pre-UAC toast guidance and verify completed Windows setup
10 files changed
+91−21
bridge/Cargo.lock+1−1@@ -50,7 +50,7 @@ checksum = "6e4de3bc4ea267985becf712dc6d9eed8b04c953b3fcfb339ebc87acd9804901" [[package]] name = "codex-bridge"-version = "0.1.0"+version = "0.1.1" dependencies = [ "base64", "serde",
bridge/Cargo.toml+1−1@@ -1,6 +1,6 @@ [package] name = "codex-bridge"-version = "0.1.0"+version = "0.1.1" edition = "2021" publish = false
bridge/PR.md+12−8@@ -11,7 +11,7 @@ and never presented as attachment to Windows desktop-owned active sessions. ## Verification -- `cargo test --locked`: 12 unit/mock tests and one HTTP integration test pass.+- `cargo test --locked`: 13 unit/mock tests and one HTTP integration test pass. - `cargo clippy --all-targets -- -D warnings`: Linux and Windows cross-target pass. - Windows release ZIP builds; root contains only executable and bridge.json. - Live arav-rog: AB 2.1.72, OpenAI.Codex 26.901.6511.0, native CLI 0.153.4.@@ -26,18 +26,22 @@ and never presented as attachment to Windows desktop-owned active sessions. - Final AB registration has one compiled-binary instance, no entry mismatch, stable port 63514, and a development pin. No install on AdomLapper. - Deployed executable SHA256:- `a636e19cbcc54b2cbd8bd77720aea1cd6782770096884f20316dd9851a0f04c8`.+ `233294b692fc7bfc7ac262afcfb0f0268af5f60455f1f1a48f9b8776f468401c` (0.1.1). - ZIP SHA256:- `7fc759f387405871385dc2703f5eca6f05e92beeb63b285f84e31b051ae6c2f2`.+ `b961fa8539ced307da6a5b225d198c1029ab11de55c1c3409389db9a3de73985` (0.1.1). ## Remaining work The role-confirmation screen advanced after explicitly selecting the existing-Engineering role. Optional demo tasks and cross-app imports were skipped. The-remaining native first-run step is Finish Windows setup, requiring the user's-UAC approval on arav-rog. The prompt was opened and user action requested. Do not-equate backend success with completion of this OS permission step or bypass it.-Keep the PR draft for review and final setup verification.+Engineering role. Optional demo tasks and cross-app imports were skipped. The user+approved Finish Windows setup's UAC prompt. The signed-in main app and saved+DESKTOP_BRIDGE_OK reply were visually verified afterward; first-run setup is complete.+Bridge 0.1.1 adds `_setupHint` and a ready-to-send `_beforeUac` AB toast payload to+describe/status/readiness/install/open responses. Setup skills require the warning+BEFORE elevation, with selected-target/caller identity, app focus, and a chat+notice in case Windows suppresses the banner. Toast clicks are never UAC consent.+No UAC prompt is re-triggered or falsely announced on an already-configured host.+Keep the PR draft for review; no merge or public release is implied. Native desktop pipe compatibility is experimental and must be rechecked when OpenAI changes the desktop build. Worktree/automation schemas were discovered, not destructive or recurring actions exercised.
bridge/bridge.json+1−1@@ -2,7 +2,7 @@ "manifest_version": 1, "name": "codex", "displayName": "Codex",- "version": "0.1.0",+ "version": "0.1.1", "description": "Compiled Rust bridge for the OpenAI Codex desktop app", "author": "Adom", "docs": "https://wiki.adom.inc/adom/codex",
bridge/src/main.rs+42−5@@ -59,6 +59,19 @@ fn finish(mut result: Value) -> Value { redact(&mut result); result }+fn setup_guidance(mut result: Value) -> Value {+ let hwnd = result["desktop"]["windows"][0]["hwnd"]+ .as_u64()+ .or_else(|| result["windows"][0]["hwnd"].as_u64());+ result["_setupHint"] = json!("Before clicking Finish setup or triggering any Codex setup step expected to request Windows elevation, send the _beforeUac AB toast on the SAME target and with the SAME caller identity. Tell the user in chat too. Send it BEFORE the secure-desktop prompt opens, not afterward. A toast acknowledgment is not UAC consent or proof of banner visibility; wait for the user to approve the native Windows prompt and verify setup completion. Do not send an upcoming-UAC warning for a read-only check or an already-completed setup.");+ result["_beforeUac"] = json!({"command":"notify_user","args":{+ "title":"Codex setup needs your approval",+ "body":"A Windows administrator (UAC) prompt is coming for Codex setup. Please approve the native Windows prompt for OpenAI's Codex/ChatGPT app to continue. This notification cannot approve it.",+ "level":"warning","durationLong":true,+ "focus":hwnd.map(|hwnd|json!({"hwnd":hwnd})).unwrap_or(json!({"app":"ChatGPT"}))+ }});+ result+} fn redact(v: &mut Value) { match v { Value::Object(map) => {@@ -152,14 +165,14 @@ impl State { } fn dispatch(&self, command: &str, mut args: Value, caller: &Caller) -> Result<Value, String> { match command {- "codex_describe" => Ok(serde_json::from_str(CATALOG).unwrap()),+ "codex_describe" => Ok(setup_guidance(serde_json::from_str(CATALOG).unwrap())), "codex_status" | "codex_readiness" => { let backend = self.rpc.lock().unwrap();- Ok(+ Ok(setup_guidance( json!({"desktop":desktop::inventory()?,"connected":backend.as_ref().is_some_and(|r|r.alive()), "transportMode":backend.as_ref().map(|r|&r.mode),"ownerThread":*self.owner.lock().unwrap(), "authCachePresent":desktop::home().join("auth.json").is_file(),"codexHome":desktop::home()}),- )+ )) } "codex_progress" => { let jobs = self.jobs.lock().unwrap();@@ -177,7 +190,9 @@ impl State { "stillRunning":j.result.is_none(),"state":if j.result.is_none(){"running"}else{"complete"},"result":j.result}), ) }- "codex_desktop_install" => desktop::install(args["acceptAgreements"] == true),+ "codex_desktop_install" => {+ desktop::install(args["acceptAgreements"] == true).map(setup_guidance)+ } "codex_desktop_uninstall" => { self.check_owner(caller)?; if args["confirm"] != true {@@ -188,7 +203,7 @@ impl State { } desktop::uninstall() }- "codex_desktop_open" => desktop::launch(),+ "codex_desktop_open" => desktop::launch().map(setup_guidance), "codex_state" => { let inventory = desktop::inventory()?; let mut shots = Vec::new();@@ -558,6 +573,28 @@ fn serve(mut req: Request, state: Arc<State>) { mod tests { use super::*; #[test]+ fn setup_hints_require_toast_before_uac_without_claiming_consent() {+ let failure = setup_guidance(json!({"success":false,"desktop":{"windows":[{"hwnd":123}]}}));+ assert_eq!(failure["success"], false);+ assert_eq!(failure["_beforeUac"]["command"], "notify_user");+ assert_eq!(failure["_beforeUac"]["args"]["focus"]["hwnd"], 123);+ assert!(failure["_setupHint"].as_str().unwrap().contains("BEFORE"));+ assert!(failure["_setupHint"]+ .as_str()+ .unwrap()+ .contains("not UAC consent"));+ assert!(failure["_beforeUac"]["args"].get("onClick").is_none());+ assert_eq!(+ setup_guidance(json!({}))["_beforeUac"]["args"]["focus"]["app"],+ "ChatGPT"+ );+ assert_eq!(+ setup_guidance(json!({"windows":[{"hwnd":456}]}))["_beforeUac"]["args"]["focus"]+ ["hwnd"],+ 456+ );+ }+ #[test] fn credential_fields_are_redacted_recursively() { let mut v = json!({"nested":[{"access_token":"secret","refreshToken":"secret","id_token":"secret"}],"account":{"type":"chatgpt"}}); redact(&mut v);
bridge/tests/http.rs+2@@ -62,6 +62,8 @@ fn loopback_health_identity_origin_and_catalog_contract() { .into_json() .unwrap(); assert_eq!(catalog["success"], true);+ assert_eq!(catalog["_beforeUac"]["command"], "notify_user");+ assert!(catalog["_setupHint"].as_str().unwrap().contains("BEFORE")); assert_eq!(catalog["verbs"].as_array().unwrap().len(), 40); let unknown: Value = agent .post(&url)
bridge/verbs.json+1−1@@ -1,6 +1,6 @@ { "bridge": "codex",- "version": "0.1.0",+ "version": "0.1.1", "verbs": [ { "name": "codex_describe",
docs/DESKTOP-BRIDGE.md+13−4@@ -42,6 +42,15 @@ Codex (package `OpenAI.Codex`). Only after actual user acceptance, pass `acceptAgreements:true`. Existing installations are left intact. Launch may foreground the app according to Windows activation behavior; observation does not. +Before a setup action expected to trigger UAC (especially **Finish setup**), send+an AB `notify_user` toast on the same selected target/caller, using the `_beforeUac`+payload returned by describe/status/install/open. It warns that a Windows prompt+is coming and asks the user to approve the native OpenAI setup prompt. Focus it+on the discovered app HWND, with a long warning duration. Send it **before**+elevation hides the normal desktop, and also tell the user in chat because Windows+may suppress banners. A toast click is not UAC consent. This guidance is conditional:+read-only checks and completed installations do not send misleading UAC warnings.+ ## Sign-in Reuse the user's own native `$CODEX_HOME/auth.json` (usually `~/.codex/auth.json`)@@ -130,10 +139,10 @@ install/read-back/uninstall/read-back. The temporary plugin was restored to abse Desktop uninstall/reinstall and single-process AB restart were also verified; account and saved thread survived. The visible ChatGPT welcome screen remained on its role-confirmation step until the existing role was explicitly selected.-Optional demo tasks and cross-app imports were skipped. The last first-run step-is native **Finish Windows setup**, which needs the user's UAC approval on the-test machine. Successful bridge/backend requests do not prove that OS setup is-complete; inspect the visible native flow and never bypass its security prompt.+Optional demo tasks and cross-app imports were skipped. The user approved the+native **Finish Windows setup** UAC prompt, and the signed-in Codex main window+was then visually verified. Successful bridge/backend requests alone do not prove+OS setup is complete; inspect the native flow and never bypass its security prompt. See the PR for final lifecycle results. Windows x64 is first; other OS installers, a dock UI, full automation/worktree action testing and third-party OAuth are not claimed. Existing CAD recordings were made in Hydrogen, not this desktop app.
skills/codex-adom/SKILL.md+6@@ -25,6 +25,12 @@ An explicit path planner is not automatically a general autorouter. Label copied ## Focused follow-ups +For Codex Desktop installation or first-run setup, read+`../codex-desktop-bridge/SKILL.md`. Before triggering a Windows UAC prompt, send+the user an AB `notify_user` warning toast on the selected host explaining that+the prompt is coming and they must approve it. Also tell them in chat; toast+delivery is not proof they saw it and a toast click is not native UAC consent.+ For "open it", "play/show the video", or "open the folder", read `../codex-adom-desktop-artifacts/SKILL.md` and complete the action on the selected desktop. For choosing Bridge capabilities or handling dialogs, read `../codex-adom-bridge-workflows/SKILL.md`. For approvals and job results, read `../codex-adom-operation-results/SKILL.md`. For Hydrogen screenshots and hero exports, read `../codex-adom-showcase/SKILL.md`. Wiki source publication, installed skill files, and instructions already loaded in a running AI thread are separate states. Verify all three when sharing a new skill. For an existing thread, provide the explicit skill path and ask it to read it; do not assume package installation retroactively changes its context.
skills/codex-desktop-bridge/SKILL.md+12@@ -17,6 +17,18 @@ deployment. Source is `bridge/` in adom/codex, not AB core. Preserve development 3. Reuse only a user-authorized staged native cache via `codex_auth_import`. Never print tokens. Preserve existing credentials, remove staging promptly, and verify account plus the visible app. Native login is the fallback.+ Before clicking **Finish setup** or another step expected to trigger UAC,+ send AB `notify_user` on the same target/caller: title "Codex setup needs your+ approval", body "A Windows administrator (UAC) prompt is coming for Codex+ setup. Please approve the native Windows prompt for OpenAI's Codex/ChatGPT+ app to continue.", level `warning`, durationLong `true`, and focus `{hwnd}`+ for the discovered desktop window (or `{app:"ChatGPT"}` before launch).+ `codex_describe`/status/install/open provide this payload as `_beforeUac`.+ Send the toast BEFORE elevation, while the normal desktop is still visible;+ also tell the user in chat because Focus Assist may hide the banner. Wait for+ actual native UAC approval, then verify the main app. Toast clicks/acknowledgments+ are not UAC approval. Do not re-trigger UAC or warn of an upcoming prompt when+ setup is already complete, and never auto-approve or bypass the secure desktop. 4. Poll every job with `codex_progress`; inspect nested `result.success`. After timeout inspect state before resubmitting a mutation. 5. `codex_desktop_tools` / `codex_desktop_tool_call` talk to the actual desktop.