Current Status
State: Audit complete; follow-up issues created.
Next action: Start #225 first. Keep #226 and #227 parked until the desktop/app-server client direction in #217/#37 is chosen.
Blocked by: None.
Waiting for: Implementation slot for #225; product decision for #226/#227.
Last verified: 2026-05-30.
Audit result:
Useful upstream commits considered:
Finish Line
Every Code has a ranked app-server parity matrix for Codex CLI changes since the fork, with each candidate classified as import, adapt, reject, or already covered.
Acceptance Criteria
Notes
This exists because Every Code did build a version of the Codex app server, so a broad Codex CLI scan should not stop at TUI/core candidates. The output should guide product-hardening work, not become a mechanical checklist.
Relationships
Current Status
State: Audit complete; follow-up issues created.
Next action: Start #225 first. Keep #226 and #227 parked until the desktop/app-server client direction in #217/#37 is chosen.
Blocked by: None.
Waiting for: Implementation slot for #225; product decision for #226/#227.
Last verified: 2026-05-30.
Audit result:
code-rs/app-server/src/transport.rsaccepts raw websocket connections and the app-server exposes command-capable requests such asExecOneOffCommand.thread/resume; Define app-server remote history redaction policy #227 defines remote-client history redaction. Both are valuable only if Every Code makes v2 app-server thread lifecycle a real client surface.code-rs; current Every Code has no editablecode-rs/exec-servercrate or upstreamfs/watchapp-server runtime surface.Useful upstream commits considered:
a027135bc6Origin-header rejection for exec-server websocket requests; adapt the browser-Origin hardening to Every Code app-server in Harden Every Code app-server websocket transport #225.51bfb5f3b1app-server websocket listener with auth guard; adapt the trust-boundary decision in Harden Every Code app-server websocket transport #225.1509ae6d8dlocal-only app-server gating through processors; audit command-capable methods in Harden Every Code app-server websocket transport #225.2a1158b8e2initial turns page onthread/resume; parked as Add initial turns page to app-server thread resume #226.7bddb3083dremote-client thread-history redaction; parked as Define app-server remote history redaction policy #227.522f549922,c579da41b1,de80fa6e31,64ead6a83a,c57dee98b7are watcher/exec-server robustness changes with no direct editable Every Code surface today.Finish Line
Every Code has a ranked app-server parity matrix for Codex CLI changes since the fork, with each candidate classified as import, adapt, reject, or already covered.
Acceptance Criteria
code-rs.Notes
This exists because Every Code did build a version of the Codex app server, so a broad Codex CLI scan should not stop at TUI/core candidates. The output should guide product-hardening work, not become a mechanical checklist.
Relationships