Handle Amazon Bedrock credentials during logout - #33175
Merged
copyberry[bot] merged 1 commit intoJul 14, 2026
Merged
Conversation
## Why Amazon Bedrock can use either a Codex-managed API key or credentials managed by AWS, so logout must not remove or misrepresent credentials that Codex does not control. ## What changed - Remove the managed Bedrock key on logout and clear `model_provider` only when its user-config value is still `amazon-bedrock`. - Reject logout for AWS-managed Bedrock credentials without changing existing authentication or configuration. - Add a `test-logout` app-server test-client command that waits for the resulting `account/updated` notification. ## Testing Add coverage for managed and AWS-managed Bedrock logout, concurrent provider changes, config reload failures, and conditional user-config cleanup. GitOrigin-RevId: a003c0ec27ad7b36d499fe7b63ab4a0dd6369b4f
copyberry
Bot
force-pushed
the
copyberry/codex-internal-to-codex-oss/a003c0ec27ad7b36d499fe7b63ab4a0dd6369b4f
branch
from
July 14, 2026 21:55
3f4c369 to
6e215e0
Compare
copyberry
Bot
deleted the
copyberry/codex-internal-to-codex-oss/a003c0ec27ad7b36d499fe7b63ab4a0dd6369b4f
branch
July 14, 2026 21:56
montella1507
temporarily deployed
to
issue-triage
July 14, 2026 21:58 — with
GitHub Actions
Inactive
montella1507
temporarily deployed
to
issue-triage
July 14, 2026 21:58 — with
GitHub Actions
Inactive
montella1507
temporarily deployed
to
issue-triage
July 14, 2026 21:58 — with
GitHub Actions
Inactive
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Handle Amazon Bedrock credentials during logout
Why
Amazon Bedrock can use either a Codex-managed API key or credentials managed by
AWS, so logout must not remove or misrepresent credentials that Codex does not
control.
What changed
model_provideronly whenits user-config value is still
amazon-bedrock.authentication or configuration.
test-logoutapp-server test-client command that waits for theresulting
account/updatednotification.Testing
Add coverage for managed and AWS-managed Bedrock logout, concurrent provider
changes, config reload failures, and conditional user-config cleanup.