## What changed
- Make automatic MCP OAuth registration prefer Client ID Metadata Documents
(CIMD) when the authorization server advertises support for public clients and
Codex is using its native loopback callback. Fall back to advertised Dynamic
Client Registration (DCR) otherwise.
- Add explicit `cimd` and `dcr` registration overrides to the CLI and app-server
OAuth login API. Validate CIMD metadata and callback URLs before starting the
authorization flow.
- Use a callback-specific Codex client metadata URL for CIMD and retain the
exact redirect URI through authorization and token exchange.
## Testing
- Cover automatic and forced CIMD selection, DCR fallback, invalid metadata and
redirects, token refresh, authenticated MCP requests, and conformance
regression checks.
GitOrigin-RevId: 4238372ca53b0f38e781e141ab5da97e0a6ddf45
## What changed
- Add a harness that runs the Codex executable against a pinned official MCP
client conformance suite across shipping, intermediate, and modern protocol
versions, HTTP and stdio transports, and OAuth scenarios.
- Add a separate app-server regression matrix for transport, security, schema,
pagination, SSE, multi-round request, and catalog-boundary behavior.
- Check both suites against committed baselines so previously passing or
required checks cannot disappear or newly fail, while keeping known failures
visible in complete reports.
- Run the fixture self-tests and both executable-level gates from the Python
and TypeScript SDK test workflows.
## Testing
- Add unit tests for the fixture server, official-suite adapter, conformance
runner, baseline comparison, and reviewer regression runner.
GitOrigin-RevId: de59f039294e34ed72873d9f6940b52e89172c0d