Skip to content

ChatGPT: authenticate in the daily browser and explicitly connect its session #592

Description

@NOirBRight

Part of #567. User-confirmed requirement: first sign-in and reauthentication must occur in the daily browser and reuse its Google / Passkey experience, rather than opening an empty dedicated profile.

Implementation candidate: a user-clicked Chromium/Chrome/Edge connector with only chatgpt.com host access sends the session through the authenticated, same-origin Runtime Settings API. The pinned browser verifies it before selecting a new account generation. The existing process/configuration remains unchanged until explicit restart. No Google credentials, passwords, Passkeys, daily profile copying, or remote debugging of the daily browser.

Acceptance:

  • Reject foreign origins, missing settings sessions, malformed/foreign-domain cookies and invalid account verification.
  • Preserve the old active account and process on save; load the verified generation only on explicit restart.
  • Real account import/restart validation on Linux using user-authorized existing ChatGPT session data; secrets excluded from evidence.
  • Extension logic rejects wrong tabs and tab-navigation races; no background collector or external destination.
  • Install the proposed extension in the operator's daily browser after reviewing its permissions.
  • Real extension-to-settings handoff in the daily browser, including Google/Passkey login when authentication is needed.
  • Same-SHA Linux/Windows portable builds, embedded revision/source/extension/runtime hashes, and no-account-file inspection.
  • Final Windows core and follow-up environment qualification: 3744 passed / 70 skipped; three fresh-checkout missing-runtime failures resolved by preparing the same embedded runtime, then the whole runtime module passed 118 / 3 skipped. Windows Rust/clippy passed.
  • Real daily-browser acceptance on Windows.

The extension requires a one-time user installation. The selected browser UX is accepted; extension deployment and real browser acceptance remain open. See ADR-0018 in the implementation branch. This issue must not auto-close from a code-only merge.

Candidate: a6d6b79b6161a3381b0a26dbfbd84750a55393c5, PR #593 stacked on #591. Linux final Python core 3602 passed / 196 skipped; Linux Rust 799 passed / 1 ignored; Windows Rust 787 passed / 3 ignored. Real isolated Chromium popup handoff with synthetic cookies passed. Windows rejection reset reproduced 5/30 before fix, then 20/20 passed after consuming the bounded request body before origin rejection. The final portable files and Chinese test instructions are in Downloads/CodexHub-test-a6d6b79b on AM01S and Yoga. No formal release or production replacement.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions