openai / openai/codex

Personal workspace: browser access blocked by “admin-enforced policy”

Open
#43,822 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

app browser bug computer-use windows-os
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

This is regarding Feedback ID: 01a080e2-a5c1-7b00-92e4-47461836bf88

I use my personal ChatGPT workspace with Codex on Windows. The current task is Codex-MC, ID 01a080e2-a5c1-7b00-92e4-47461836bf88. On September 8, 2026, the Unified Computer Use tool could list my existing Chrome dashboard tab but refused to read it at http://127.0.0.1:8765/ with: "The admin-enforced policy blocks this action."

My local configuration already explicitly allows that browser origin, and the browser developer-access toggle is enabled. The documented ProgramData/OpenAI/Codex requirements.toml and managed_config.toml files are absent at the checked locations. A fresh successor task with the available browser/computer plugins reproduced the failure. Earlier attempts in the predecessor task also failed after changing the permission profile.

Please identify the effective deny rule and its provenance for this task: the policy key/value, source layer or policy ID, scope, and the responsible owner. Please distinguish a managed policy from a configuration-loading problem or product defect. If there is an intended supported way to permit agent testing of this local dashboard, please provide the exact setting or supported correction. I am requesting normal access to this local dashboard, not a security bypass or public exposure.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the documented ProgramData/OpenAI/Codex/requirements.toml and managed_config.toml locations, then reproduce the denial against the local dashboard at http://127.0.0.1:8765/ using the Unified Computer Use tool and available browser/computer plugins. Done means identifying the effective policy key/value, source layer or policy ID, scope, and owner, and distinguishing a managed policy from configuration loading or a product defect.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
authorization, desktop, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.