diff --git a/packages/server/src/server/agent/providers/codex-mcp-agent.test.ts b/packages/server/src/server/agent/providers/codex-mcp-agent.test.ts index f560ce1f3..8c44ed2b4 100644 --- a/packages/server/src/server/agent/providers/codex-mcp-agent.test.ts +++ b/packages/server/src/server/agent/providers/codex-mcp-agent.test.ts @@ -541,7 +541,7 @@ describe("CodexMcpAgentClient (MCP integration)", () => { provider: "codex-mcp", cwd, modeId: "full-access", - approvalPolicy: "on-request", + approvalPolicy: "untrusted", } as AgentSessionConfig; let session: AgentSession | null = null; @@ -676,7 +676,7 @@ describe("CodexMcpAgentClient (MCP integration)", () => { provider: "codex-mcp", cwd, modeId: "full-access", - approvalPolicy: "on-request", + approvalPolicy: "untrusted", } as AgentSessionConfig; let session: AgentSession | null = null; @@ -751,7 +751,7 @@ describe("CodexMcpAgentClient (MCP integration)", () => { provider: "codex-mcp", cwd, modeId: "full-access", - approvalPolicy: "on-request", + approvalPolicy: "untrusted", } as AgentSessionConfig; let session: AgentSession | null = null; @@ -837,7 +837,7 @@ describe("CodexMcpAgentClient (MCP integration)", () => { provider: "codex-mcp", cwd, modeId: "full-access", - approvalPolicy: "on-request", + approvalPolicy: "untrusted", } as AgentSessionConfig; let session: AgentSession | null = null; diff --git a/packages/server/src/server/agent/providers/codex-mcp-agent.ts b/packages/server/src/server/agent/providers/codex-mcp-agent.ts index 547ed6289..89da6acbd 100644 --- a/packages/server/src/server/agent/providers/codex-mcp-agent.ts +++ b/packages/server/src/server/agent/providers/codex-mcp-agent.ts @@ -98,7 +98,7 @@ const MODE_PRESETS: Record< sandbox: "read-only", }, auto: { - approvalPolicy: "on-request", + approvalPolicy: "untrusted", sandbox: "workspace-write", }, "full-access": { @@ -559,7 +559,6 @@ class CodexMcpAgentSession implements AgentSession { this.pendingPermissionHandlers.delete(requestId); this.pendingPermissions.delete(requestId); this.resolvedPermissionRequests.add(requestId); - const status = response.behavior === "allow" ? "granted" : "denied"; this.emitEvent({ type: "timeline", diff --git a/plan.md b/plan.md index fc06b491f..ed81745f7 100644 --- a/plan.md +++ b/plan.md @@ -59,12 +59,13 @@ Build a new Codex MCP provider side‑by‑side with the existing Codex SDK prov - The reference supports permissions - copy the working approach. - **Done (2025-12-24 18:53)**: Matched happy-cli elicitation flow by avoiding duplicate permission requests when exec events pre-seed pending entries and aligned permission tool naming with CodexBash. -- [ ] **Fix**: Test `approval-policy=untrusted` instead of `on-request`. +- [x] **Fix**: Test `approval-policy=untrusted` instead of `on-request`. - Happy CLI uses `"untrusted"` for default mode, voice-dev uses `"on-request"`. - `"on-request"` may not trigger MCP elicitation. - Change MODE_PRESETS["auto"] to use `"untrusted"` and test if real elicitation works. - If it works, remove the synthetic permission gating workaround. + - **Done (2025-12-24 19:12)**: Switched default auto approval policy to untrusted and updated permission tests; ran `vitest run codex-mcp-agent.test.ts` twice and elicitation still failed (missing permission requests, plus existing timeline/runtime failures), so kept permission gating fallback. - [x] **Fix**: Use valid model instead of gpt-4.1. @@ -73,6 +74,25 @@ Build a new Codex MCP provider side‑by‑side with the existing Codex SDK prov - Update tests and provider to use a valid default model. - **Done (2025-12-24 18:58)**: Updated Codex MCP default model to gpt-5.1-codex and switched runtime info test to use the valid model id. +- [ ] **Fix**: Remove hardcoded default model - passthrough user choice. + + - Pass `config.model` if user specifies one. + - If user doesn't specify, omit `model` field - let Codex CLI pick its default. + - Do NOT hardcode any fallback model in the provider. + - Tests should not specify a model unless testing model passthrough. + +- [ ] **Review**: Flag ALL workarounds/hacks in `codex-mcp-agent.ts` - they are NOT acceptable. + + - Read the entire file and list every workaround, fallback, or synthetic behavior. + - Known workarounds to remove: + - `queuePermissionGatedEvent` - synthetic permission gating + - `ensurePermissionRequestFromEvent` - creating fake permission requests + - `pendingToolEvents` queue - hack to defer events + - `exec_approval_request` handler - workaround for missing elicitation + - `modelRejected` fallback logic + - For each: explain what real fix is needed instead. + - These hacks hide bugs. The provider should work correctly or fail clearly. + - [ ] **Fix**: Resolve typecheck errors in `codex-mcp-agent.ts`. - Run `npm run typecheck --workspace=@paseo/server`.