Skip to main content

AuthManager

Struct AuthManager 

Source
pub struct AuthManager { /* private fields */ }
Expand description

Central manager providing a single source of truth for auth.json derived authentication data. It loads once (or on preference change) and then hands out cloned CodexAuth values so the rest of the program has a consistent snapshot.

External modifications to auth.json will NOT be observed until reload() is called explicitly. This matches the design goal of avoiding different parts of the program seeing inconsistent auth data mid‑run.

Implementations§

Source§

impl AuthManager

Source

pub async fn new( codex_home: PathBuf, enable_codex_api_key_env: bool, auth_credentials_store_mode: AuthCredentialsStoreMode, forced_chatgpt_workspace_id: Option<Vec<String>>, chatgpt_base_url: Option<String>, keyring_backend_kind: AuthKeyringBackendKind, auth_route_config: AuthRouteConfig, ) -> Self

Create a new manager loading the initial auth using the provided preferred auth method. Errors loading auth are swallowed; auth() will simply return None in that case so callers can treat it as an unauthenticated state.

Source

pub fn from_auth_for_testing(auth: CodexAuth) -> Arc<Self>

Create an AuthManager with a specific CodexAuth, for testing only.

Source

pub fn from_auth_for_testing_with_home( auth: CodexAuth, codex_home: PathBuf, ) -> Arc<Self>

Create an AuthManager with a specific CodexAuth and codex home, for testing only.

Source

pub fn external_bearer_only(config: ModelProviderAuthInfo) -> Arc<Self>

Source

pub fn auth_cached(&self) -> Option<CodexAuth>

Current cached auth (clone) without attempting a refresh.

Source

pub fn auth_change_receiver(&self) -> Receiver<u64>

Subscribes to cached auth changes that can affect request recovery.

Source

pub fn refresh_failure_for_auth( &self, auth: &CodexAuth, ) -> Option<RefreshTokenFailedError>

Source

pub async fn auth(&self) -> Option<CodexAuth>

Current cached auth (clone). May be None if not logged in or load failed. For managed ChatGPT auth that needs a proactive refresh, first performs a guarded reload and then refreshes only if the on-disk auth is unchanged.

Source

pub async fn agent_identity_auth( &self, policy: AgentIdentityAuthPolicy, session_source: SessionSource, ) -> Result<Option<AgentIdentityAuth>>

Source

pub async fn reload(&self) -> bool

Reloads auth from the active source. Returns whether the auth value changed.

Source

pub async fn set_external_auth( &self, external_auth: Arc<dyn ExternalAuth>, ) -> Result<(), RefreshTokenError>

Source

pub fn clear_external_auth(&self)

Source

pub fn set_forced_chatgpt_workspace_id(&self, workspace_id: Option<Vec<String>>)

Source

pub fn forced_chatgpt_workspace_id(&self) -> Option<Vec<String>>

Source

pub fn has_external_auth(&self) -> bool

Source

pub fn is_external_chatgpt_auth_active(&self) -> bool

Source

pub fn codex_api_key_env_enabled(&self) -> bool

Source

pub async fn shared( codex_home: PathBuf, enable_codex_api_key_env: bool, auth_credentials_store_mode: AuthCredentialsStoreMode, forced_chatgpt_workspace_id: Option<Vec<String>>, chatgpt_base_url: Option<String>, keyring_backend_kind: AuthKeyringBackendKind, auth_route_config: AuthRouteConfig, ) -> Arc<Self>

Convenience constructor returning an Arc wrapper.

Source

pub async fn shared_from_config( config: &impl AuthManagerConfig, enable_codex_api_key_env: bool, ) -> Arc<Self>

Convenience constructor returning an Arc wrapper from resolved config.

Source

pub fn unauthorized_recovery(self: &Arc<Self>) -> UnauthorizedRecovery

Source

pub async fn refresh_token(&self) -> Result<(), RefreshTokenError>

Attempt to refresh the token by first performing a guarded reload from the active auth source. If the loaded token differs from the cached token, we can assume that the source already refreshed it. Otherwise, ask the token authority to refresh.

Source

pub async fn refresh_token_from_authority( &self, ) -> Result<(), RefreshTokenError>

Attempt to refresh the current auth token from the authority that issued it and update the shared cache. If the token refresh fails, returns the error to the caller.

Source

pub async fn logout(&self) -> Result<bool>

Log out by deleting the on‑disk auth.json (if present). Returns Ok(true) if a file was removed, Ok(false) if no auth file existed. On success, reloads the in‑memory auth cache so callers immediately observe the unauthenticated state.

Source

pub async fn logout_with_revoke(&self) -> Result<bool>

Source

pub fn get_api_auth_mode(&self) -> Option<AuthMode>

Returns the precise kind of credentials backing the current authentication.

Source

pub fn auth_mode(&self) -> Option<AuthMode>

Returns the effective backend auth mode for the current authentication.

Source

pub fn current_auth_uses_codex_backend(&self) -> bool

Trait Implementations§

Source§

impl Debug for AuthManager

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

Source§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

Source§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

Source§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> AsTypeStaticRegistered for T

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> ErasedDestructor for T
where T: 'static,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FutureExt for T

Source§

fn with_context(self, otel_cx: Context) -> WithContext<Self>

Attaches the provided Context to this type, returning a WithContext wrapper. Read more
Source§

fn with_current_context(self) -> WithContext<Self>

Attaches the current Context to this type, returning a WithContext wrapper. Read more
Source§

impl<T> HasTyVTable for T
where T: ?Sized,

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> IntoRequest<T> for T

Source§

fn into_request(self) -> Request<T>

Wrap the input message T in a tonic::Request
Source§

impl<L> LayerExt<L> for L

Source§

fn named_layer<S>(&self, service: S) -> Layered<<L as Layer<S>>::Service, S>
where L: Layer<S>,

Applies the layer to a service and wraps it in Layered.
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T, U> RamaFrom<T> for U
where U: From<T>,

Source§

fn rama_from(value: T) -> U

Source§

impl<T, U, CrateMarker> RamaInto<U, CrateMarker> for T
where U: RamaFrom<T, CrateMarker>,

Source§

fn rama_into(self) -> U

Source§

impl<T, U> RamaTryFrom<T> for U
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

Source§

fn rama_try_from(value: T) -> Result<U, <U as RamaTryFrom<T>>::Error>

Source§

impl<T, U, CrateMarker> RamaTryInto<U, CrateMarker> for T
where U: RamaTryFrom<T, CrateMarker>,

Source§

type Error = <U as RamaTryFrom<T, CrateMarker>>::Error

Source§

fn rama_try_into(self) -> Result<U, <U as RamaTryFrom<T, CrateMarker>>::Error>

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> StarlarkAnyBound for T
where T: Debug + Send + Sync + 'static,

Source§

impl<T> ToAst for T

Source§

fn ast(self, begin: usize, end: usize) -> Spanned<Self>

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more