Desktop: Chrome permission requested again despite repeated authorization in the same task
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 125k
- Forks
- 19.4k
- PR merge metrics
- PR metrics pending
Description
Bug
Codex desktop asked for permission to use Chrome again during an ongoing website validation task, despite the user having explicitly authorized Chrome use multiple times in the same task. The user reported the repeated permission card and explicitly requested this bug report.
Expected
Retain authorization for the same browser and task across continued work. Ask again only when the action or permission scope materially changes.
Observed context
The agent was opening the existing Chrome profile and a browser tab to inspect deployment setup. The tool output did not expose the permission card itself; the duplicate-card observation is user-reported, not independently captured in a screenshot.
Related earlier failures in this task: Safari navigation repeatedly returned an automatic permission approval review deadline timeout after approximately 90 seconds; native Safari pointer actions temporarily returned noWindowsAvailable while accessibility reads worked. Native Safari pointer actions later recovered in a restored app session. Causality between these symptoms is unconfirmed.
Environment
macOS, Codex/ChatGPT desktop version 26.903.71938 observed during this task, unified-computer-use mcp__cua_repl. September 14, 2026.
No private project files, credentials, financial data, session transcript, or browser history attached. Please investigate permission persistence and duplicate approval prompts during task continuation.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the Chrome authorization flow in the Codex desktop app on macOS, continuing multiple browser actions within one task and observing permission state. Compare this with a materially changed action or scope. Done means authorization persists for the same browser and task, while a new prompt appears only when the action or scope changes.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- macos, rust
- Domain
- desktop, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100