Skip to content

Releases: buidangminh23/codex-mcp-bridge

v1.21.0

Choose a tag to compare

@github-actions github-actions released this 06 Oct 13:12
74faed5

Added

  • Resume an accepted Codex Desktop delivery after a timeout with wait_codex_reply, using its original delivery ID without resending the prompt.
  • Inspect and prepare the selected workspace through inspect_bridge_project and prepare_bridge_project, with shared project grants, registered worktree support and explicit revocation.
  • Add bridge-projects for project policy management and codex-bridge-code-install for explicit, previewable Claude Code MCP registration. Include Desktop handoff and new-machine onboarding guides.

Fixed

  • Authenticate native creation receipt contents with a private persisted signing key; reject altered and unsigned receipts before restoring ownership.
  • Restore owned task authority from verified native creation receipts after lost acknowledgements or bridge restarts. Keep ordinary inspection and editable local receipts subject to ownership checks.
  • Bind project grants to repository identity and retain repository and registered worktree revocations when Git metadata or directories disappear or are replaced. Reject malformed Git metadata instead of treating it as a plain folder.
  • Recheck live project, account and runtime authority after awaited sender validation before opening, trusting or submitting a Claude Desktop creation.
  • Preserve reply continuation for confirmed Desktop creation and for existing-thread sends whose native acknowledgement times out. Return an owner/account-bound delivery ID without resending; keep uncertain delivery distinct from acceptance, and correlate creation replies to the exact native creation dispatch. Retain the upstream project and permission checks.
  • Bind standalone Git directory pointers to their checkout so a different project cannot impersonate an authorized recipient. Reject private metadata, task receipts and connector credentials that grow, disappear or change while being read.
  • Read release fingerprints through bounded file descriptors, preserve locks replaced by another writer, and refuse automatic expiry of an occupied telemetry lock. Write installer output atomically and stop if the Desktop configuration changes before replacement.
  • Refuse app-server health redirects and revalidate loopback endpoints before use. Clamp supervisor timer intervals to the supported range and restrict CI token permissions while pinning the Deno setup action.
  • Create Windows private files and directories with a protected access list owned by the current user; reject unsafe existing artifacts instead of retaining inherited or foreign explicit access entries.

Upgrade notes

  • Update the installed npm package to @minhspark/codex-mcp-bridge@1.21.0 and reconnect the existing Desktop MCP connections. Publication does not reload already running MCP processes or prove a live Desktop handoff.
  • Shared project policy is opt-in. Configure both bridge MCP entries with the same absolute CODEX_BRIDGE_PROJECT_POLICY JSON path when using shared grants; project grants do not change session permissions.
  • At release preparation, 91 new CodeQL alerts from PR #100 remain open. Static triage did not establish an exploitable security boundary for 86 alerts; five file-reading race alerts still require validation. This release does not claim a clean CodeQL alert inventory.

v1.20.1

Choose a tag to compare

@github-actions github-actions released this 03 Oct 01:49
e0f40b5

Fixed

  • Start the Sites connector through symbolic installation paths, including the Windows NVM directory junction. Resolve the entry point before comparing it with the module path, so the installed command polls its paired Site instead of silently exiting.

v1.20.0

Choose a tag to compare

@github-actions github-actions released this 03 Oct 01:29
53d474f

Added

  • Codex MCP Bridge plugin package and a public Sites MCP server. Each account pairs its own computer; users can access only their paired connector and its allowed local projects. Public ChatGPT directory publication remains subject to developer verification and review.
  • Outbound HTTPS Desktop connector with account binding, private credentials, persistent operation receipts, and live pairing checks before sending work. Duplicate operation IDs cannot send the same prompt again; interrupted sends remain uncertain until inspected.
  • Hosted Worker source, D1 migrations, pairing UI, plugin compatibility manifest, workflow skill, and Windows/macOS setup instructions.

v1.19.7

Choose a tag to compare

@github-actions github-actions released this 02 Oct 13:46
c7ecdfd

Fixed

  • Recover dormant Claude Desktop Code tasks by reopening their exact saved task ID before sending. Keep account, sender, project and recipient checks active throughout recovery; never substitute a CLI or another task.
  • On Windows, submit authorized new Desktop conversations after verifying the exact prompt and explicitly selecting the full native project path. A deep-link folder hint can otherwise create a scratch "No folder" session. Authorized workspace trust handles only the exact native project dialog. Preserve uncertain submission receipts without duplicate Send and track native helper changes during runtime reload.
  • Recover the Windows Claude URI launcher when an application update leaves the registered executable missing.

v1.19.6

Choose a tag to compare

@github-actions github-actions released this 02 Oct 05:18
00730b6

Fixed

  • Make newly created Linux and macOS managed Codex policies readable by the account running Codex. Repair an existing valid policy that was created with restrictive file permissions, so Full access + Never works after administrator setup and remains repairable on later bridge starts.

v1.19.5

Choose a tag to compare

@github-actions github-actions released this 02 Oct 04:53
3197a58

Added

  • Add an explicit --full-access installer option that sets Codex Full access + Never globally, repairs the managed policy on Windows, macOS, and Linux with OS administrator authentication when needed, and restores the chosen settings on later bridge connections.

v1.19.4

Choose a tag to compare

@github-actions github-actions released this 02 Oct 04:12
b417091

Fixed

  • Detect a managed Codex requirements.toml whose allowed_sandbox_modes omits read-only before auto-starting an external app-server. The bridge and npm run check now report the policy error directly instead of waiting for a generic connection failure; they do not edit the administrator-managed file.

v1.19.3

Choose a tag to compare

@github-actions github-actions released this 30 Sep 10:55
c2e9d0d

Changed

  • Write the analytics branch with the Repository analytics workflow's own token. Its hourly commits were pushed with ANALYTICS_TOKEN, a personal token, so they were attributed to the repository owner and GitHub showed the owner an "analytics had recent pushes" banner with a "Compare & pull request" button after every run. The commits now come from github-actions[bot]. ANALYTICS_TOKEN only reads GitHub traffic and no longer needs write access (fine-grained: Administration read).

Fixed

  • Refuse Claude-to-Codex Desktop delivery into another project even when send_to_codex_thread omits cwd or supplies the recipient's directory. The bridge now compares the independently verified Claude caller with the destination before creation, rename, navigation and prompt delivery, and checks both directory/repository identities and the current native destination again at the socket write. Broad allowed roots and thread overrides cannot authorize a different project. Subfolders and registered worktrees of the same repository remain usable; drive/home repositories do not absorb unrelated projects. Blocked preflight calls report that no Desktop mutation was dispatched.

v1.19.2

Choose a tag to compare

@github-actions github-actions released this 29 Sep 16:18
9518806

Fixed

  • Start both bridges from project-local npm installations. When npm hoists the bridge's dependencies into the project's node_modules, the package has no node_modules of its own, and preparing the immutable runtime failed with ENOENT (scandir …node_modules) since 1.15.0; only global installs, which keep a nested node_modules, started. The runtime now copies the dependency tree Node resolves from the package (hoisted, nested, scoped, aliased, linked and peer dependencies) and nothing else from the project, so it stays isolated from later installation changes. Its revision also covers the project's npm lock, so an npm install that changes those dependencies reloads the bridge.
  • Stop the Codex bridge cleanly when its MCP client disconnects. The bridge ends the Windows PowerShell caller checks it started and waits for them to close, and the supervisor gives its worker up to 6 seconds to exit before stopping it. Before, the supervisor stopped the worker after 1 second without waiting, which left those checks running with the bridge's working directory in use. On Windows, deleting that directory right after a test closed its bridge then failed with EPERM; the tests no longer retry that deletion.

v1.19.1

Choose a tag to compare

@github-actions github-actions released this 29 Sep 14:38
f6bb13a

Fixed

  • Recognize codex_work_desktop as a local Desktop sender while retaining exact host task/turn, workspace, and lifecycle checks (#84). Its permission profile is classified like that of any other Codex Desktop task, including the managed sandboxes supported since 1.19.0 (#83). Claude's inbound policy and permission parity checks are unchanged.
  • Read completed native replies from codex_work_desktop tasks and correlate both raw and XML-escaped Desktop dispatch envelopes to the exact sent prompt (#84). Task, workspace, turn, executor, and pre-send watermark checks remain required for automatic reply observation.
  • Preserve confirmed native send acceptance when the overall response deadline expires (#84). The timeout does not release the underlying operation's thread lock, retry a prompt, or turn an unconfirmed send into a successful delivery.
  • Avoid a Windows Node 24.13.0 native crash when preparing supervisor and MCP contract test fixtures from a Unicode checkout path by awaiting asynchronous directory copies (#84).
  • Stop refusing Claude → Codex callers on Windows because Windows PowerShell started slowly (#42). The caller check reads the process ancestry in a fresh Windows PowerShell that first compiles its Toolhelp helper, and the five-second fail-closed deadline covered that startup as well as the read. On a cold or contended machine the startup alone has taken 5 to 15 seconds: CI refused callers with INSPECTION_TIMEOUT before the script had begun (5,036 ms) and while the helper was still compiling (5,017 ms), although the read itself takes about 60 ms. The helper now reports when it is ready, and the five-second deadline starts there. Getting ready has its own 25-second ceiling, so a whole read still ends within the 30 seconds the bridge gives its other PowerShell identity reads. Either expiry still refuses the caller, and a slow start is reported as INSPECTOR_START_TIMEOUT. The helper also writes its JSON itself, so the timed read no longer loads PowerShell's JSON serializer.
  • Lock ip-address at 10.7.2 for development installs (#87). 10.5.0 misclassified IPv6 link-local and NAT64 local-use addresses. The bridge's stdio servers never load the rate-limiting code that uses it, and the published package ships no lockfile, so installs from npm resolve their own versions.