Files
codex/codex-rs
cooper-oai 5ed321ce00 Protect workload identity auth in app-server account RPCs (#38426)
## Why

Workload identity credentials are owned by the app-server host and must not be replaced, removed, or exported through client account operations.

## What changed

- Reject account login and logout RPCs while workload identity is selected.
- Continue reporting the active authentication method from `getAuthStatus`, but omit the host-owned token even when `includeToken` is requested.

GitOrigin-RevId: 750c9d07ed2f4ba7007bbe75f188573e79749647
2026-08-13 20:04:57 +00:00
..
2026-07-29 13:53:15 +00:00
2026-07-29 13:53:15 +00:00