Problem
load_codex_cli_credential() accepts a Codex CLI access_token containing only whitespace. CodexChatModel then treats it as a loaded credential and builds an invalid Authorization header instead of following the existing missing-credential path.
Reproduction
Against upstream e2feca1, point CODEX_AUTH_PATH to a JSON file containing:
Observed behavior:
load_codex_cli_credential() -> CodexCliCredential(access_token=' ', ...)
repr(headers["Authorization"]) -> 'Bearer '
The same behavior occurs for the legacy token field and the nested tokens.access_token field when their value is whitespace-only. For a padded non-empty token, the captured header representation is Bearer codex-access-token\\n, so the request retains the padding.
Expected behavior
Normalize string tokens before validation. Empty or whitespace-only values should return no credential and cause the existing Codex CLI credential not found error during model initialization. Valid tokens with surrounding whitespace should be normalized before request construction.
Affected area
Backend model credential loading and the Codex provider initialization/request boundary. No endpoint, API schema, or external service is required to reproduce the behavior; the exact outbound header can be asserted with an offline request capture.
Problem
load_codex_cli_credential()accepts a Codex CLIaccess_tokencontaining only whitespace.CodexChatModelthen treats it as a loaded credential and builds an invalidAuthorizationheader instead of following the existing missing-credential path.Reproduction
Against upstream
e2feca1, pointCODEX_AUTH_PATHto a JSON file containing:{"access_token": " "}Observed behavior:
The same behavior occurs for the legacy
tokenfield and the nestedtokens.access_tokenfield when their value is whitespace-only. For a padded non-empty token, the captured header representation isBearer codex-access-token\\n, so the request retains the padding.Expected behavior
Normalize string tokens before validation. Empty or whitespace-only values should return no credential and cause the existing
Codex CLI credential not founderror during model initialization. Valid tokens with surrounding whitespace should be normalized before request construction.Affected area
Backend model credential loading and the Codex provider initialization/request boundary. No endpoint, API schema, or external service is required to reproduce the behavior; the exact outbound header can be asserted with an offline request capture.