Repository navigation
Releases: buidangminh23/codex-mcp-bridge
Releases · buidangminh23/codex-mcp-bridge
Release list
v1.21.0
Added
- Resume an accepted Codex Desktop delivery after a timeout with
wait_codex_reply, using its original delivery ID without resending the prompt. - Inspect and prepare the selected workspace through
inspect_bridge_projectandprepare_bridge_project, with shared project grants, registered worktree support and explicit revocation. - Add
bridge-projectsfor project policy management andcodex-bridge-code-installfor explicit, previewable Claude Code MCP registration. Include Desktop handoff and new-machine onboarding guides.
Fixed
- Authenticate native creation receipt contents with a private persisted signing key; reject altered and unsigned receipts before restoring ownership.
- Restore owned task authority from verified native creation receipts after lost acknowledgements or bridge restarts. Keep ordinary inspection and editable local receipts subject to ownership checks.
- Bind project grants to repository identity and retain repository and registered worktree revocations when Git metadata or directories disappear or are replaced. Reject malformed Git metadata instead of treating it as a plain folder.
- Recheck live project, account and runtime authority after awaited sender validation before opening, trusting or submitting a Claude Desktop creation.
- Preserve reply continuation for confirmed Desktop creation and for existing-thread sends whose native acknowledgement times out. Return an owner/account-bound delivery ID without resending; keep uncertain delivery distinct from acceptance, and correlate creation replies to the exact native creation dispatch. Retain the upstream project and permission checks.
- Bind standalone Git directory pointers to their checkout so a different project cannot impersonate an authorized recipient. Reject private metadata, task receipts and connector credentials that grow, disappear or change while being read.
- Read release fingerprints through bounded file descriptors, preserve locks replaced by another writer, and refuse automatic expiry of an occupied telemetry lock. Write installer output atomically and stop if the Desktop configuration changes before replacement.
- Refuse app-server health redirects and revalidate loopback endpoints before use. Clamp supervisor timer intervals to the supported range and restrict CI token permissions while pinning the Deno setup action.
- Create Windows private files and directories with a protected access list owned by the current user; reject unsafe existing artifacts instead of retaining inherited or foreign explicit access entries.
Upgrade notes
- Update the installed npm package to
@minhspark/codex-mcp-bridge@1.21.0and reconnect the existing Desktop MCP connections. Publication does not reload already running MCP processes or prove a live Desktop handoff. - Shared project policy is opt-in. Configure both bridge MCP entries with the same absolute
CODEX_BRIDGE_PROJECT_POLICYJSON path when using shared grants; project grants do not change session permissions. - At release preparation, 91 new CodeQL alerts from PR #100 remain open. Static triage did not establish an exploitable security boundary for 86 alerts; five file-reading race alerts still require validation. This release does not claim a clean CodeQL alert inventory.
v1.20.1
Fixed
- Start the Sites connector through symbolic installation paths, including the Windows NVM directory junction. Resolve the entry point before comparing it with the module path, so the installed command polls its paired Site instead of silently exiting.
v1.20.0
Added
- Codex MCP Bridge plugin package and a public Sites MCP server. Each account pairs its own computer; users can access only their paired connector and its allowed local projects. Public ChatGPT directory publication remains subject to developer verification and review.
- Outbound HTTPS Desktop connector with account binding, private credentials, persistent operation receipts, and live pairing checks before sending work. Duplicate operation IDs cannot send the same prompt again; interrupted sends remain uncertain until inspected.
- Hosted Worker source, D1 migrations, pairing UI, plugin compatibility manifest, workflow skill, and Windows/macOS setup instructions.
v1.19.7
Fixed
- Recover dormant Claude Desktop Code tasks by reopening their exact saved task ID before sending. Keep account, sender, project and recipient checks active throughout recovery; never substitute a CLI or another task.
- On Windows, submit authorized new Desktop conversations after verifying the exact prompt and explicitly selecting the full native project path. A deep-link folder hint can otherwise create a scratch "No folder" session. Authorized workspace trust handles only the exact native project dialog. Preserve uncertain submission receipts without duplicate Send and track native helper changes during runtime reload.
- Recover the Windows Claude URI launcher when an application update leaves the registered executable missing.
v1.19.6
Fixed
- Make newly created Linux and macOS managed Codex policies readable by the account running Codex. Repair an existing valid policy that was created with restrictive file permissions, so Full access + Never works after administrator setup and remains repairable on later bridge starts.
v1.19.5
Added
- Add an explicit
--full-accessinstaller option that sets Codex Full access + Never globally, repairs the managed policy on Windows, macOS, and Linux with OS administrator authentication when needed, and restores the chosen settings on later bridge connections.
v1.19.4
Fixed
- Detect a managed Codex
requirements.tomlwhoseallowed_sandbox_modesomitsread-onlybefore auto-starting an external app-server. The bridge andnpm run checknow report the policy error directly instead of waiting for a generic connection failure; they do not edit the administrator-managed file.
v1.19.3
Changed
- Write the
analyticsbranch with theRepository analyticsworkflow's own token. Its hourly commits were pushed withANALYTICS_TOKEN, a personal token, so they were attributed to the repository owner and GitHub showed the owner an "analytics had recent pushes" banner with a "Compare & pull request" button after every run. The commits now come fromgithub-actions[bot].ANALYTICS_TOKENonly reads GitHub traffic and no longer needs write access (fine-grained: Administration read).
Fixed
- Refuse Claude-to-Codex Desktop delivery into another project even when
send_to_codex_threadomitscwdor supplies the recipient's directory. The bridge now compares the independently verified Claude caller with the destination before creation, rename, navigation and prompt delivery, and checks both directory/repository identities and the current native destination again at the socket write. Broad allowed roots and thread overrides cannot authorize a different project. Subfolders and registered worktrees of the same repository remain usable; drive/home repositories do not absorb unrelated projects. Blocked preflight calls report that no Desktop mutation was dispatched.
v1.19.2
Fixed
- Start both bridges from project-local npm installations. When npm hoists the bridge's dependencies into the project's
node_modules, the package has nonode_modulesof its own, and preparing the immutable runtime failed withENOENT(scandir …node_modules) since 1.15.0; only global installs, which keep a nestednode_modules, started. The runtime now copies the dependency tree Node resolves from the package (hoisted, nested, scoped, aliased, linked and peer dependencies) and nothing else from the project, so it stays isolated from later installation changes. Its revision also covers the project's npm lock, so annpm installthat changes those dependencies reloads the bridge. - Stop the Codex bridge cleanly when its MCP client disconnects. The bridge ends the Windows PowerShell caller checks it started and waits for them to close, and the supervisor gives its worker up to 6 seconds to exit before stopping it. Before, the supervisor stopped the worker after 1 second without waiting, which left those checks running with the bridge's working directory in use. On Windows, deleting that directory right after a test closed its bridge then failed with
EPERM; the tests no longer retry that deletion.
v1.19.1
Fixed
- Recognize
codex_work_desktopas a local Desktop sender while retaining exact host task/turn, workspace, and lifecycle checks (#84). Its permission profile is classified like that of any other Codex Desktop task, including the managed sandboxes supported since 1.19.0 (#83). Claude's inbound policy and permission parity checks are unchanged. - Read completed native replies from
codex_work_desktoptasks and correlate both raw and XML-escaped Desktop dispatch envelopes to the exact sent prompt (#84). Task, workspace, turn, executor, and pre-send watermark checks remain required for automatic reply observation. - Preserve confirmed native send acceptance when the overall response deadline expires (#84). The timeout does not release the underlying operation's thread lock, retry a prompt, or turn an unconfirmed send into a successful delivery.
- Avoid a Windows Node 24.13.0 native crash when preparing supervisor and MCP contract test fixtures from a Unicode checkout path by awaiting asynchronous directory copies (#84).
- Stop refusing Claude → Codex callers on Windows because Windows PowerShell started slowly (#42). The caller check reads the process ancestry in a fresh Windows PowerShell that first compiles its Toolhelp helper, and the five-second fail-closed deadline covered that startup as well as the read. On a cold or contended machine the startup alone has taken 5 to 15 seconds: CI refused callers with
INSPECTION_TIMEOUTbefore the script had begun (5,036 ms) and while the helper was still compiling (5,017 ms), although the read itself takes about 60 ms. The helper now reports when it is ready, and the five-second deadline starts there. Getting ready has its own 25-second ceiling, so a whole read still ends within the 30 seconds the bridge gives its other PowerShell identity reads. Either expiry still refuses the caller, and a slow start is reported asINSPECTOR_START_TIMEOUT. The helper also writes its JSON itself, so the timed read no longer loads PowerShell's JSON serializer. - Lock
ip-addressat 10.7.2 for development installs (#87). 10.5.0 misclassified IPv6 link-local and NAT64 local-use addresses. The bridge's stdio servers never load the rate-limiting code that uses it, and the published package ships no lockfile, so installs from npm resolve their own versions.