Skip to content

[bug] Codex CLI accepts whitespace-only access tokens #5958

Description

@xbzz1018

Problem

load_codex_cli_credential() accepts a Codex CLI access_token containing only whitespace. CodexChatModel then treats it as a loaded credential and builds an invalid Authorization header instead of following the existing missing-credential path.

Reproduction

Against upstream e2feca1, point CODEX_AUTH_PATH to a JSON file containing:

{"access_token": "   "}

Observed behavior:

load_codex_cli_credential() -> CodexCliCredential(access_token='   ', ...)
repr(headers["Authorization"]) -> 'Bearer   '

The same behavior occurs for the legacy token field and the nested tokens.access_token field when their value is whitespace-only. For a padded non-empty token, the captured header representation is Bearer codex-access-token\\n, so the request retains the padding.

Expected behavior

Normalize string tokens before validation. Empty or whitespace-only values should return no credential and cause the existing Codex CLI credential not found error during model initialization. Valid tokens with surrounding whitespace should be normalized before request construction.

Affected area

Backend model credential loading and the Codex provider initialization/request boundary. No endpoint, API schema, or external service is required to reproduce the behavior; the exact outbound header can be asserted with an offline request capture.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-triageAwaiting maintainer triage

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions