Secure browser auth is unavailable on Chrome sign-in forms
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 125k
- Forks
- 19.4k
- PR merge metrics
- PR metrics pending
Description
Summary
The Codex Chrome extension is connected, but secure browserAuth and secure form elicitation are not advertised on an app sign-in form.
Expected behavior
Codex should expose secure auth/form capabilities so a local smoke account can authenticate without direct credential entry.
Actual behavior
The sign-in page exposes only pageAssets and cdp. No credentials were entered or accessed.
Impact
This blocks a synthetic production-smoke workflow. No customer or family data has been changed.
Environment
- Codex Desktop on Windows, updated and restarted
- Chrome connected through the official extension
- Feedback ID:
01a07d1e-d529-7121-82bc-c4e2e311571f
Reproduction
- Start a local Codex task with
@Chrome. - Open an application sign-in form.
- Inspect the advertised capabilities without entering credentials.
- Observe that secure browser auth and secure form elicitation are absent.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the issue with Codex Desktop on Windows, the official Chrome extension, and a local task using @Chrome; inspect the capabilities advertised on an application sign-in form. Done means secure browserAuth and secure form elicitation are advertised while no credentials are entered or accessed.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, desktop, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100