Skip to content

feat(chatgpt): authorize through the daily browser - #593

Draft
NOirBRight wants to merge 3 commits into
fix/chatgpt-login-upgrade-guidancefrom
feat/chatgpt-daily-browser-login
Draft

NOirBRight wants to merge 3 commits into
fix/chatgpt-login-upgrade-guidancefrom
feat/chatgpt-daily-browser-login

Conversation

@NOirBRight

@NOirBRight NOirBRight commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Summary

First sign-in and reauthentication now use the daily browser so Google / Passkey can reuse that browser's existing session.

Daily browser signs in to ChatGPT
  → user clicks the ChatGPT-only extension on Runtime Settings
  → authenticated same-origin transfer
  → pinned browser verifies the candidate account
  → save selected account; explicit component restart activates it

Stacked on #591. Tracks #592; keep the issue open pending real daily-browser acceptance. No formal release or production installation is included.

Evidence

  • Before: the separate login profile prompted for Google sign-in again.
    After: product login opens ChatGPT in the daily browser; the extension transfers only ChatGPT cookies after an explicit click.
  • Linux: Python core 3602 passed / 196 skipped; Rust 799 passed / 1 ignored; clippy passed. Final account/settings checks: 43 passed. Extension logic: 4 passed.
  • Real Chromium extension popup and authenticated same-origin handoff passed in an isolated profile with synthetic cookies.
  • An authorized existing ChatGPT session passed real pinned-browser verification in an isolated runtime. Saving preserved its PID/config; explicit restart loaded the selected account; test account files were deleted afterward.
  • Final candidate: a6d6b79. Fixed Windows portable resource omission and an intermittent Windows socket reset on foreign-origin rejection (5/30 failures before; 20/20 passed after bounded body consumption before rejection). Final Linux core: 3602 passed / 196 skipped. Final Windows core: 3744 passed / 70 skipped with three missing-embedded-runtime environment failures in the fresh validation checkout; after preparing the same runtime, the complete runtime module passed 118 / 3 skipped. No unresolved failures. Windows Rust: 787 passed / 3 ignored; clippy passed. Linux final portable physical pointer test passed.
  • User installation and Google / Passkey handoff in the actual daily browser remain unverified. Firefox/Safari are not implemented. Authentication does not imply connector/tool readiness.

Merge Danger

Door: two-way

Existing legacy account state remains supported. The running runtime keeps its current account until explicit restart. Older builds do not understand the selected-account generation pointer.

Blast Radius: authentication

New authenticated local account import and persistence. Extension permissions are activeTab, scripting, cookies, and only https://chatgpt.com/*; no Google credentials or Passkeys are exported. Failed verification preserves the prior selection.

Portable artifacts from a6d6b79 are in Downloads/CodexHub-test-a6d6b79b on both hosts. Embedded revisions, Python/extension source, runtime hashes and absence of account/database/log files were verified; the Windows ZIP was verified again after transfer. Draft status is retained for real daily-browser acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant