paperclip/server/src/routes
Nicky Leach 9064cfd09e
feat(codex-local): give each Codex account its own home and path secret (#12709)
## Thinking Path

> - Paperclip is the control plane for companies that use AI agents for
work
> - Local adapters connect Paperclip agents to provider command line
tools
> - The Codex adapter stores login data in a shared company home
> - A shared home cannot keep credentials for more than one Codex
account
> - This pull request gives each account a safe home and a matching
company secret
> - The benefit is that one company can use multiple Codex accounts at
the same time

## Linked Issues or Issue Description

**Problem or motivation**

A company can hold only one Codex subscription credential because device
login uses one shared home. A second account cannot log in without
replacing or conflicting with the first credential.

**Proposed solution**

This change validates the vendor account identifier, stores each
credential in its own home, and creates a company secret that points to
that home. Repeat login calls return success when the matching secret
already exists.

**Roadmap alignment**

The change supports the roadmap goal for centrally managed secrets with
scoped access and audited resolution.

**Additional context**

The security review returned approve with no blocking finding. The
branch adds shared account-handle validation and tests for device login
and the Codex local adapter.

## What Changed

- Add strict allowlist validation for Codex account handles.
- Store each Codex account credential in a separate home under the Codex
cache root.
- Verify that the resolved account home stays inside the cache root.
- Create the `CODEX_HOME_<handle>` company secret for each account.
- Keep repeat and concurrent login calls safe and idempotent.
- Add shared helper and route, adapter, and validation tests.

## Verification

- `pnpm --filter @paperclipai/adapter-codex-local test` passes with 343
tests.
- `pnpm --filter @paperclipai/server test
src/__tests__/agent-device-login-routes.test.ts` passes with 25 tests.
- The adapter suite passes with 23 tests.
- The shared package and Codex adapter typechecks pass.
- Continuous integration must pass on every check before merge.

## Risks

The account handle becomes part of a directory path and secret name. The
strict allowlist and root containment check reduce path traversal risk.
Existing single-account homes remain unchanged unless a new device login
creates an account-specific home.

## Model Used

OpenAI GPT-5 (exact runtime model ID: gpt-5), with tool use and code
execution. The runtime context window is not exposed in this run.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-02 14:46:53 -07:00
..
access.ts Gate Paperclip Runner setup behind an experimental flag (#12656) 2026-09-01 05:57:40 -05:00
activity.ts build(deps): bump zod from 3.25.76 to 4.4.3 (#11719) 2026-08-21 00:04:14 -07:00
adapter-login-route-spine.ts feat(auth): normalize agent login in the sandbox onto one session table and a capability contract (#11730) 2026-08-19 11:51:31 -07:00
adapters.test.ts feat: add Grok device login to the sandbox login panel (#12469) 2026-08-28 21:48:34 -07:00
adapters.ts Remove cheap model profiles (#12683) 2026-09-01 14:57:38 -05:00
agents.ts feat(codex-local): give each Codex account its own home and path secret (#12709) 2026-09-02 14:46:53 -07:00
approvals.ts Remove cheap model profiles (#12683) 2026-09-01 14:57:38 -05:00
assets.ts Remove the company brand color and per-company attachment limit (#12291) 2026-08-27 12:11:05 -07:00
attention.ts feat(decisions): improve desk triage and queue parity (#10785) 2026-08-03 21:31:45 -05:00
auth.ts feat(server): split the Sentry DSN into front-end and backend variables (#12678) 2026-09-01 11:02:04 -07:00
authz.ts feat(secrets): thread the acting user into user-scoped secret resolution (#10115) 2026-07-23 13:30:26 -07:00
board-chat.ts feat(secrets): add user-specific runtime secrets (#8825) 2026-07-05 05:58:20 -05:00
built-in-agents.ts [codex] Add built-in agents and Reflection Coach bundle (#9206) 2026-07-09 16:29:30 -05:00
cases.ts Remove the company brand color and per-company attachment limit (#12291) 2026-08-27 12:11:05 -07:00
cloud.ts feat: make in-app features cloud-aware (#10850) 2026-08-04 23:00:14 -05:00
companies.ts feat: hideable company settings pages, with import floored on cloud-managed instances (#12199) 2026-08-25 16:06:35 -07:00
company-import-paths.ts [codex] Runtime control-plane fixes (#6380) 2026-05-20 10:37:11 -05:00
company-skill-policy.ts feat(skills): open-by-default company skill policy and core UX (#9564) 2026-07-15 11:42:40 -05:00
company-skills.ts Add project folder browsing to skill imports (#9930) 2026-08-02 10:55:36 -05:00
connection-intents.test.ts feat(connections): add self-serve intent runtime (#12345) 2026-08-29 12:08:34 -05:00
connection-intents.ts feat(connections): add self-serve intent runtime (#12345) 2026-08-29 12:08:34 -05:00
costs.ts security(server): close cross-tenant existence oracle (404 instead of 403) (#3967) 2026-07-14 15:53:09 -07:00
dashboard.ts feat(server): recovery observability report and rate alert (#9644) 2026-07-16 02:34:00 -05:00
decision-queues.ts feat(decisions): add desk workflow and retention (#10672) 2026-08-02 10:47:03 -05:00
decision-training.ts build(deps): bump zod from 3.25.76 to 4.4.3 (#11719) 2026-08-21 00:04:14 -07:00
decisions.ts build(deps): bump zod from 3.25.76 to 4.4.3 (#11719) 2026-08-21 00:04:14 -07:00
environment-selection.ts refactor(environments): make execution environments instance-scoped (#8375) 2026-06-20 09:42:53 -07:00
environments.ts feat: environment delete with agent reassignment and consented sandbox destroy (#12053) 2026-08-23 16:53:17 -07:00
execution-workspaces.ts feat(apps): improve gateway and workspace connection UX (#12340) 2026-08-29 12:08:32 -05:00
file-resources.ts build(deps): bump zod from 3.25.76 to 4.4.3 (#11719) 2026-08-21 00:04:14 -07:00
folders.ts feat: stamp responsible users on activity logs (#9731) 2026-07-16 20:54:55 -05:00
goals.ts security(server): close cross-tenant existence oracle (404 instead of 403) (#3967) 2026-07-14 15:53:09 -07:00
health.ts feat: operator-configurable settings visibility via PAPERCLIP_HIDDEN_SETTINGS (#11823) 2026-08-20 17:54:44 -07:00
inbox-agent-policy.ts feat: stamp responsible users on activity logs (#9731) 2026-07-16 20:54:55 -05:00
inbox-dismissals.ts feat: stamp responsible users on activity logs (#9731) 2026-07-16 20:54:55 -05:00
index.ts feat(runner): add managed provider backends (#12699) 2026-09-02 00:48:30 -05:00
instance-database-backups.ts feat: make in-app features cloud-aware (#10850) 2026-08-04 23:00:14 -05:00
instance-settings.ts Clean up experimental settings features (#12681) 2026-09-01 14:23:05 -05:00
issue-tree-control.ts feat: stamp responsible users on activity logs (#9731) 2026-07-16 20:54:55 -05:00
issues-checkout-wakeup.ts Cut over OpenClaw adapter to strict SSE streaming 2026-03-05 15:54:55 -06:00
issues.ts feat(work-products): add rich cards and run artifact inventory (#12717) 2026-09-02 15:27:54 -05:00
llms.ts [codex] Add built-in Hermes adapters (#8543) 2026-06-26 16:04:58 -05:00
managed-agent-profiles.ts feat(runner): add managed provider backends (#12699) 2026-09-02 00:48:30 -05:00
onboarding-seed.ts feat(server): receive and apply the Paperclip Cloud onboarding seed (#11098) 2026-08-12 22:54:07 -07:00
openapi.ts feat(work-products): add rich cards and run artifact inventory (#12717) 2026-09-02 15:27:54 -05:00
org-chart-svg.ts Improve generated company org chart assets 2026-03-23 16:58:07 -05:00
pipelines.ts build(deps): bump zod from 3.25.76 to 4.4.3 (#11719) 2026-08-21 00:04:14 -07:00
plugin-ui-static.ts feat(mcp) [split 2/8]: add governed access contracts (#9557) 2026-07-14 12:57:20 -05:00
plugins.ts feat: operator-configurable settings visibility via PAPERCLIP_HIDDEN_SETTINGS (#11823) 2026-08-20 17:54:44 -07:00
projects.ts feat(apps): improve gateway and workspace connection UX (#12340) 2026-08-29 12:08:32 -05:00
remote-agent-profiles.ts feat(runner): add managed provider backends (#12699) 2026-09-02 00:48:30 -05:00
resource-memberships.ts feat(server): add per-user document stars (#9952) 2026-07-27 19:13:35 -05:00
routines.ts fix(workspaces): attach PR preparation to existing branches (#11703) 2026-08-21 17:23:18 -05:00
secrets.ts Add governed secret alias confirmation cards (#11486) 2026-08-18 09:44:24 -05:00
setup-token-route.test.ts fix(setup-token): pin the start guard to the served adapter (#12179) 2026-08-25 19:48:44 -07:00
sidebar-badges.ts feat: add attention queue and Decisions surface (#9380) 2026-07-10 17:09:57 -05:00
sidebar-preferences.ts feat: stamp responsible users on activity logs (#9731) 2026-07-16 20:54:55 -05:00
smoke-lab.ts feat: stamp responsible users on activity logs (#9731) 2026-07-16 20:54:55 -05:00
status-cards.ts feat(status-cards): join summary-mentioned issues to watched set (#10205) 2026-07-24 16:44:56 -05:00
summary-slots.ts feat: add built-in summarizer and summary slots (#9713) 2026-07-17 11:03:07 -05:00
teams-catalog.ts [codex] Add teams catalog extraction (#7550) 2026-06-05 12:55:49 -05:00
tool-access-connection-intent.test.ts Simplify app connections and enable managed Google access (#12728) 2026-09-02 14:05:53 -05:00
tool-access.ts Simplify app connections and enable managed Google access (#12728) 2026-09-02 14:05:53 -05:00
tool-gateway.ts feat(runner): add Codex-native application integration (#12591) 2026-08-31 14:38:38 -05:00
user-profiles.ts Skill Studio: three-pane skill IDE with sandboxed test runs (#9241) 2026-07-09 13:08:56 -05:00
workspace-command-authz.ts feat(workspaces): defer isolated setup until runtime start (#10653) 2026-08-02 10:37:10 -05:00
workspace-runtime-service-authz.ts feat(runtime): managed Tailscale HTTPS lifecycle, durable runtime leases, and bounded control recovery (#11525) 2026-08-17 06:23:33 -04:00