Hide expired OAuth tokens from the account token list - #2004
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9cf8e6a793
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| oauth := token.OAuthClientID != "" || strings.HasPrefix(token.Name, "OAuth: ") | ||
| if oauth && !token.ExpiresAt.IsZero() && !token.ExpiresAt.After(now) { |
There was a problem hiding this comment.
Avoid treating user-named PATs as OAuth grants
A personal token can be created with any name, including OAuth: backup, while CreateToken leaves its OAuthClientID empty. Once that token expires, this prefix check misclassifies it as a legacy OAuth grant and removes it from both the HTML and JSON token listings, unlike every other expired personal token, so its owner can no longer discover or delete it through the account UI/API. Use authoritative OAuth metadata or otherwise disambiguate legacy grants from user-controlled names.
AGENTS.md reference: AGENTS.md:L567-L567
Useful? React with 👍 / 👎.
OAuth access tokens expire after 24 hours, but ListTokens still returned every expired grant. Reconnecting ChatGPT therefore left unusable entries accumulating on the account Tokens page.
Exclude expired OAuth grants from the shared account token listing, covering both the HTML page and JSON response. Recognize current OAuthClientID metadata and older OAuth-prefixed entries. Active and non-expiring OAuth grants remain visible. Personal tokens and admin OAuth audit records retain their existing behavior; this does not extend token validity or delete credentials.
Verified with
go test -race ./internal/auth ./account -short,go build -buildvcs=false ./...andgit diff --check. Regression coverage includes legacy entries, active grants, account isolation and retained audit records. No layout changes; authenticated browser verification was unavailable.