What version of the Codex App are you using?
ChatGPT/Codex Desktop 26.721.41059 (build 5848)
What platform is your computer?
macOS on Apple Silicon
What issue are you seeing?
A conversation visibly configured for Full Access still stops and displays a terminal approval dialog with Deny and Allow once controls.
The approval was requested for an ordinary external CLI command that reads a remote document over HTTPS. No destructive operation was involved. Full Access remained visibly selected in the composer while the approval dialog was shown.
This started occurring recently; the same workflow previously ran without per-command approval prompts.
No screenshots are attached because the original dialog contains private document identifiers and command arguments.
Steps to reproduce
- Open ChatGPT/Codex Desktop on macOS.
- Set the conversation permission mode to Full Access.
- In an existing or long-running conversation, ask Codex to invoke an authenticated third-party CLI that reads a remote document over HTTPS.
- Observe that Codex pauses and requests terminal approval even though Full Access is still visibly selected.
The behavior appears to be consistent with a stale or incorrectly propagated approval context. It may be more likely after resuming an existing conversation or changing permissions during an active task.
Expected behavior
With Full Access selected, routine terminal, filesystem, and network operations should run without a per-command approval prompt.
If a permission change cannot affect the active turn, the UI should clearly indicate that the change only applies after the task is restarted instead of showing Full Access as active.
Actual behavior
The UI shows Full Access, but the active task behaves as if it is still using an approval-required policy and displays an Allow once dialog.
Workarounds observed
Stopping the active run and starting a fresh conversation with Full Access selected before the first prompt may avoid the issue. Existing affected conversations may continue using the stale approval context.
Related issues
This report confirms the behavior is still observable on Desktop version 26.721.41059.
What version of the Codex App are you using?
ChatGPT/Codex Desktop
26.721.41059(build5848)What platform is your computer?
macOS on Apple Silicon
What issue are you seeing?
A conversation visibly configured for Full Access still stops and displays a terminal approval dialog with Deny and Allow once controls.
The approval was requested for an ordinary external CLI command that reads a remote document over HTTPS. No destructive operation was involved. Full Access remained visibly selected in the composer while the approval dialog was shown.
This started occurring recently; the same workflow previously ran without per-command approval prompts.
No screenshots are attached because the original dialog contains private document identifiers and command arguments.
Steps to reproduce
The behavior appears to be consistent with a stale or incorrectly propagated approval context. It may be more likely after resuming an existing conversation or changing permissions during an active task.
Expected behavior
With Full Access selected, routine terminal, filesystem, and network operations should run without a per-command approval prompt.
If a permission change cannot affect the active turn, the UI should clearly indicate that the change only applies after the task is restarted instead of showing Full Access as active.
Actual behavior
The UI shows Full Access, but the active task behaves as if it is still using an approval-required policy and displays an Allow once dialog.
Workarounds observed
Stopping the active run and starting a fresh conversation with Full Access selected before the first prompt may avoid the issue. Existing affected conversations may continue using the stale approval context.
Related issues
This report confirms the behavior is still observable on Desktop version
26.721.41059.