rowboat/apps/x
Prakhar Pandey a1db0e395a feat: Sign in with ChatGPT — OAuth sign-in, token storage, and settings UI
Lets users connect their ChatGPT Plus/Pro subscription instead of pasting
an API key. Sign-in half only: the codex model client consumes the session
via getChatGPTAccessToken().

- PKCE OAuth against auth.openai.com using the official Codex CLI public
  client id (constants verified against the openai/codex sources); system
  browser + loopback callback server on the pre-registered fixed port
  127.0.0.1:1455, state validated, stale callbacks rejected
- token store (core): single config/chatgpt-auth.json holding non-secret
  display fields (email, accountId, expiresAt) plus the token material
  encrypted via the safeStorage cipher bridge (plaintext-with-marker
  fallback when no keychain, matching the GitHub token path); no token
  value ever written in the clear or logged
- getChatGPTAccessToken(): single-flight refresh within 5 min of expiry;
  refresh rejection (400/401) clears to a clean signed-out state and
  throws typed ChatGPTAuthRequiredError; 5xx/network kept as transient
- sign-out with best-effort token revocation
- IPC chatgpt:getStatus/signIn/cancelSignIn/signOut — raw tokens never
  cross to the renderer; real cancellation settles the in-flight attempt,
  frees the port, and a retry starts a fresh attempt (new PKCE/state)
- settings UI: ChatGPT Subscription section on the OpenAI card
  (sign in / waiting + cancel / connected as {email} + sign out) via a
  useChatGPT hook

Vitest covers the token store, single-flight refresh, and
transient-vs-terminal refresh handling.
2026-07-17 17:23:46 +05:30
..
.pnpm-store/v11 add talking mascot 2026-07-02 22:20:11 +05:30
apps feat: Sign in with ChatGPT — OAuth sign-in, token storage, and settings UI 2026-07-17 17:23:46 +05:30
docs feat(apps): M3 UI — catalog, D18 install dialog, publish dialog, detail actions 2026-07-06 15:34:54 +05:30
packages feat: Sign in with ChatGPT — OAuth sign-in, token storage, and settings UI 2026-07-17 17:23:46 +05:30
.gitignore feat(x): reference-based model requests + wire-form composer 2026-07-02 14:20:44 +05:30
ANALYTICS.md feat(x): client auto-update with restart card and inline release notes (#744) 2026-07-16 17:59:03 +05:30
CODE_MODE_ENGINES_PLAN.md Code mode: make packaged builds work via managed engine provisioning (#625) 2026-06-17 21:53:15 +05:30
demo.gif add gif 2026-07-10 10:04:37 +05:30
eslint.config.mts ignore renderer eslint 2026-01-16 12:05:33 +05:30
GRANOLA_PARITY.md feat(x): resident app — launch at login + menu bar tray (Granola parity phase 1) 2026-07-13 21:02:20 +05:30
LIVE_NOTE.md docs(x): design docs and prompt catalogs follow the runtime/ move 2026-07-10 16:30:26 +05:30
MINI_APPS_PLAN.md feat(mini-apps): copilot builder — build-mini-app skill + install/data tools 2026-07-01 01:25:45 +05:30
package.json ci(x): typecheck test files — the gap vitest and the build tsconfigs both miss 2026-07-10 16:30:26 +05:30
pnpm-lock.yaml feat(x): client auto-update with restart card and inline release notes (#744) 2026-07-16 17:59:03 +05:30
pnpm-workspace.yaml build(x): graft vscode-jsonrpc onto langium via packageExtensions 2026-07-07 02:45:09 +05:30
tsconfig.base.json bootstrap new electron app 2026-01-16 12:05:33 +05:30
VIDEO_MODE.md docs(x): fix pointers the reorg docs pass got wrong or missed 2026-07-10 17:57:03 +05:30