paperclip/packages/shared/src
Nicky Leach 9064cfd09e
feat(codex-local): give each Codex account its own home and path secret (#12709)
## Thinking Path

> - Paperclip is the control plane for companies that use AI agents for
work
> - Local adapters connect Paperclip agents to provider command line
tools
> - The Codex adapter stores login data in a shared company home
> - A shared home cannot keep credentials for more than one Codex
account
> - This pull request gives each account a safe home and a matching
company secret
> - The benefit is that one company can use multiple Codex accounts at
the same time

## Linked Issues or Issue Description

**Problem or motivation**

A company can hold only one Codex subscription credential because device
login uses one shared home. A second account cannot log in without
replacing or conflicting with the first credential.

**Proposed solution**

This change validates the vendor account identifier, stores each
credential in its own home, and creates a company secret that points to
that home. Repeat login calls return success when the matching secret
already exists.

**Roadmap alignment**

The change supports the roadmap goal for centrally managed secrets with
scoped access and audited resolution.

**Additional context**

The security review returned approve with no blocking finding. The
branch adds shared account-handle validation and tests for device login
and the Codex local adapter.

## What Changed

- Add strict allowlist validation for Codex account handles.
- Store each Codex account credential in a separate home under the Codex
cache root.
- Verify that the resolved account home stays inside the cache root.
- Create the `CODEX_HOME_<handle>` company secret for each account.
- Keep repeat and concurrent login calls safe and idempotent.
- Add shared helper and route, adapter, and validation tests.

## Verification

- `pnpm --filter @paperclipai/adapter-codex-local test` passes with 343
tests.
- `pnpm --filter @paperclipai/server test
src/__tests__/agent-device-login-routes.test.ts` passes with 25 tests.
- The adapter suite passes with 23 tests.
- The shared package and Codex adapter typechecks pass.
- Continuous integration must pass on every check before merge.

## Risks

The account handle becomes part of a directory path and secret name. The
strict allowlist and root containment check reduce path traversal risk.
Existing single-account homes remain unchanged unless a new device login
creates an account-specific home.

## Model Used

OpenAI GPT-5 (exact runtime model ID: gpt-5), with tool use and code
execution. The runtime context window is not exposed in this run.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-02 14:46:53 -07:00
..
app-definitions Simplify app connections and enable managed Google access (#12728) 2026-09-02 14:05:53 -05:00
runtime-exposure fix(workspaces): make managed runtimes reliable across restarts (#11740) 2026-08-19 14:55:16 -05:00
telemetry feat(runner): add Codex-native application integration (#12591) 2026-08-31 14:38:38 -05:00
types feat(work-products): add rich cards and run artifact inventory (#12717) 2026-09-02 15:27:54 -05:00
validators Simplify app connections and enable managed Google access (#12728) 2026-09-02 14:05:53 -05:00
account-handle.test.ts feat(codex-local): give each Codex account its own home and path secret (#12709) 2026-09-02 14:46:53 -07:00
account-handle.ts feat(codex-local): give each Codex account its own home and path secret (#12709) 2026-09-02 14:46:53 -07:00
adapter-agnostic-keys.test.ts
…
adapter-auth-check-code.test.ts feat(auth): normalize agent login in the sandbox onto one session table and a capability contract (#11730) 2026-08-19 11:51:31 -07:00
adapter-auth-check-code.ts feat(auth): normalize agent login in the sandbox onto one session table and a capability contract (#11730) 2026-08-19 11:51:31 -07:00
adapter-auth-session.ts Add sandbox device-login for the Codex adapter (#11237) 2026-08-12 08:58:25 -07:00
adapter-type.ts
…
adapter-types.test.ts
…
agent-eligibility.test.ts feat(agents): warn when an agent's escalation path routes to a paused manager (#10657) 2026-08-01 17:42:42 -07:00
agent-eligibility.ts feat(agents): warn when an agent's escalation path routes to a paused manager (#10657) 2026-08-01 17:42:42 -07:00
agent-url-key.ts
…
api.ts feat: maintained in_review review-path contract + stalled-review actions (#10675) 2026-08-04 13:54:40 -05:00
app-definitions-url.test.ts feat(apps): expand the self-serve connection catalog (#12344) 2026-08-29 12:08:34 -05:00
app-definitions.generated.ts feat(apps): expand the self-serve connection catalog (#12344) 2026-08-29 12:08:34 -05:00
app-definitions.ingestion-report.json feat(apps): expand the self-serve connection catalog (#12344) 2026-08-29 12:08:34 -05:00
app-definitions.test.ts Simplify app connections and enable managed Google access (#12728) 2026-09-02 14:05:53 -05:00
app-definitions.ts fix(apps): complete managed Google Workspace rollout (#12619) 2026-08-31 19:06:11 -05:00
company-import-transfer.test.ts feat: already-imported transfer error names the landed company (#12144) 2026-08-25 13:51:50 -07:00
company-import-transfer.ts feat: already-imported transfer error names the landed company (#12144) 2026-08-25 13:51:50 -07:00
config-schema.test.ts fix(config): preserve extensions and guard invalid repairs (#11005) 2026-08-07 00:41:19 -05:00
config-schema.ts build(deps): bump zod from 3.25.76 to 4.4.3 (#11719) 2026-08-21 00:04:14 -07:00
connection-intent-guidance.test.ts feat(connections): add self-serve intent runtime (#12345) 2026-08-29 12:08:34 -05:00
connection-intent-guidance.ts feat(connections): add self-serve intent runtime (#12345) 2026-08-29 12:08:34 -05:00
constants.ts Remove cheap model profiles (#12683) 2026-09-01 14:57:38 -05:00
decision.test.ts feat(decisions): add first-class propose mode (#10010) 2026-07-31 19:17:02 -07:00
document-anchors.test.ts
…
document-anchors.ts
…
env-file.test.ts fix(config): preserve env files during managed updates (#10980) 2026-08-07 00:54:43 -05:00
env-file.ts fix(config): preserve env files during managed updates (#10980) 2026-08-07 00:54:43 -05:00
environment-custom-images.test.ts
…
environment-custom-images.ts
…
environment-support.test.ts feat: add kimi-local adapter for Kimi Code CLI (CLI + ACP engines) (#9967) 2026-08-20 12:06:33 -07:00
environment-support.ts feat: add kimi-local adapter for Kimi Code CLI (CLI + ACP engines) (#9967) 2026-08-20 12:06:33 -07:00
execution-workspace-guards.ts
…
external-objects-server.ts
…
external-objects.test.ts
…
external-objects.ts
…
feature-catalog.test.ts
…
feature-catalog.ts fix(runner): restore local session and task integrity (#12721) 2026-09-02 16:11:26 -05:00
frontmatter.test.ts
…
frontmatter.ts build(deps): bump zod from 3.25.76 to 4.4.3 (#11719) 2026-08-21 00:04:14 -07:00
gitignore-runtime.test.ts
…
google-workspace-connectors.ts feat(apps): expand the self-serve connection catalog (#12344) 2026-08-29 12:08:34 -05:00
home-paths.test.ts
…
home-paths.ts
…
humanize-connection.test.ts
…
humanize-connection.ts
…
index.ts feat(codex-local): give each Codex account its own home and path secret (#12709) 2026-09-02 14:46:53 -07:00
issue-attribution.test.ts
…
issue-attribution.ts
…
issue-references.test.ts
…
issue-references.ts
…
issue-thread-interactions.test.ts feat(runner): project native runs into task threads (#12321) 2026-08-29 19:26:20 -05:00
issue-write-denial.test.ts feat(issues): explain cross-task agent writes with attribution, audit receipts, and actionable denials (#10843) 2026-08-04 23:02:51 -05:00
issue-write-denial.ts feat(issues): explain cross-task agent writes with attribution, audit receipts, and actionable denials (#10843) 2026-08-04 23:02:51 -05:00
markdown-work-products.test.ts feat(artifacts): bridge Markdown work products into the document review surface (#11822) 2026-08-20 17:28:01 -07:00
markdown-work-products.ts feat(artifacts): bridge Markdown work products into the document review surface (#11822) 2026-08-20 17:28:01 -07:00
mcp-config-help-prompt.ts feat(apps): add secure remote MCP and PostHog setup (#12339) 2026-08-29 12:08:32 -05:00
mcp-remote-headers.test.ts feat(apps): add secure remote MCP and PostHog setup (#12339) 2026-08-29 12:08:32 -05:00
mcp-remote-headers.ts feat(apps): add secure remote MCP and PostHog setup (#12339) 2026-08-29 12:08:32 -05:00
network-bind.ts
…
node-version.ts fix(build): enforce Node 24 across Paperclip (#11792) 2026-08-21 10:17:52 -07:00
oauth-endpoint-url.test.ts feat(apps): add secure remote MCP and PostHog setup (#12339) 2026-08-29 12:08:32 -05:00
oauth-endpoint-url.ts feat(apps): add secure remote MCP and PostHog setup (#12339) 2026-08-29 12:08:32 -05:00
pipeline-case-type.ts
…
pipeline-health.test.ts
…
pipeline-health.ts
…
portability-fidelity.test.ts Replace host-to-host Cloud Sync with full-fidelity company Import/Export (#10507) 2026-07-30 11:37:00 -07:00
portability-fidelity.ts Replace host-to-host Cloud Sync with full-fidelity company Import/Export (#10507) 2026-07-30 11:37:00 -07:00
portability-hash.ts Replace host-to-host Cloud Sync with full-fidelity company Import/Export (#10507) 2026-07-30 11:37:00 -07:00
portability-zip.test.ts fix(server): raise company import zip upload limit to 1 GB and make it operator-configurable (#11184) 2026-08-10 12:47:03 -07:00
portability-zip.ts fix(server): raise company import zip upload limit to 1 GB and make it operator-configurable (#11184) 2026-08-10 12:47:03 -07:00
project-mentions.test.ts
…
project-mentions.ts
…
project-url-key.ts
…
resource-memberships.test.ts feat(server): add per-user document stars (#9952) 2026-07-27 19:13:35 -05:00
responsible-user-denial.test.ts
…
responsible-user-denial.ts
…
routine-variables.test.ts
…
routine-variables.ts
…
self-serve-mcp-research.json feat(apps): expand the self-serve connection catalog (#12344) 2026-08-29 12:08:34 -05:00
self-serve-mcp-research.ts feat(apps): expand the self-serve connection catalog (#12344) 2026-08-29 12:08:34 -05:00
setting-defaults.test.ts Let operators supply defaults for selected instance settings (#12285) 2026-08-27 11:29:05 -07:00
setting-defaults.ts Let operators supply defaults for selected instance settings (#12285) 2026-08-27 11:29:05 -07:00
settings-visibility.test.ts Let operators hide the Provider vaults and Proposals tabs (#12284) 2026-08-27 11:28:15 -07:00
settings-visibility.ts Remove the instance Heartbeats settings page (#12282) 2026-08-27 11:31:43 -07:00
summary-slot.test.ts fix: isolate execution workspace summaries (#10790) 2026-08-11 08:56:32 -04:00
trust-policy.ts fix(auth): clarify protected-agent assignment blocks (#10893) 2026-08-05 10:09:17 -05:00
work-product.test.ts
…
workspace-commands.test.ts feat(apps): improve gateway and workspace connection UX (#12340) 2026-08-29 12:08:32 -05:00
workspace-commands.ts feat(apps): improve gateway and workspace connection UX (#12340) 2026-08-29 12:08:32 -05:00
workspace-file-resource.test.ts fix(files): only highlight accessible workspace file links (#11090) 2026-08-11 12:11:45 -04:00
worktree-port-registry.test.ts fix(workspaces): make managed runtimes reliable across restarts (#11740) 2026-08-19 14:55:16 -05:00
worktree-port-registry.ts fix(workspaces): make managed runtimes reliable across restarts (#11740) 2026-08-19 14:55:16 -05:00
worktree-seed-source.test.ts fix(workspaces): seed managed worktrees when the base checkout has no config (#11752) 2026-08-20 08:42:16 -07:00
worktree-seed-source.ts fix(workspaces): seed managed worktrees when the base checkout has no config (#11752) 2026-08-20 08:42:16 -07:00