src/vs/platform/agentHost/common/codexSessionConfigKeys.ts

114 LOC · 114 covered · 0 uncovered · 13 ranges · 25 concepts · 7 introducers · 13 tests

File neighbourhood

The centred file is linked to every concept that introduces one of its ranges, every test that runs code from the file, and the gray connector concepts standing between those tests and the file's own introducer concepts. Undirected links join concepts to every file where they introduce source and concepts to the tests they introduce; arrows show specialization between the displayed concepts and bridge only concepts omitted from this view. Concept colors match the source ranges below; connector concepts have no source color and are shown in gray.

Focused file, its introducer and connector concepts, their introduced files, and tests that run code from the file

In the embedded map, ordinary wheel input scrolls the page; use the visible controls to zoom and drag to pan. Open the full-screen map for canvas navigation: wheel pans, Ctrl/Command plus wheel zooms, and arrow keys pan when this region is focused. On touch screens, open the full-screen map to pan or pinch. If JavaScript or WebGL is unavailable, use the related-file, concept, and source links on this page.

Focused file, its introducer and connector concepts, their introduced files, and tests that run code from the filesrc/vs/platform/agentHost/node/codex/codexAgent.ts · 4389 LOCcodex/codexAgent.tssrc/vs/platform/agentHost/node/codex/codexSessionConfigKeys.ts · 197 LOCcodex/codexSessionConfig…src/vs/platform/agentHost/node/codex/codexSessionMetadataStore.ts · 112 LOCcodex/codexSessionMetada…codexAgent.ts ×13 · 83 introduced LOCcodexAgent.ts ×13codexSessionConfigKeys.test|title=codexSessionConfigKeys resolveSessionConfig preserves legacy read-only permissions on restore|occurrence=1 · 0 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.test|title=codexSessionConfigKeys resolveSessionConfig exposes a single permissions-preset chip|occurrence=1 · 0 introduced LOCcodexSessionConfigKeys.t…codexAgent.ts ×1 · 27 introduced LOCcodexAgent.ts ×1codexAgent.ts ×24 · 89 introduced LOCcodexAgent.ts ×24codexSessionConfigKeys.ts ×1 · 7 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×1 · 2 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×7 · 49 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×1 · 11 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×1 · 2 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×2 · 4 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×3 · 18 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×3 · 19 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×2 · 3 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×2 · 2 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×6 · 23 introduced LOCcodexSessionConfigKeys.t…codexAgent.ts ×1 · 2 introduced LOCcodexAgent.ts ×1codexAgent.ts ×1 · 2 introduced LOCcodexAgent.ts ×1codexAgent.ts ×3 · 7 introduced LOCcodexAgent.ts ×3codexAgent.ts ×1 · 2 introduced LOCcodexAgent.ts ×1codexAgent.ts ×1 · 2 introduced LOCcodexAgent.ts ×1codexAgent.ts ×1 · 2 introduced LOCcodexAgent.ts ×1codexAgent.ts ×1 · 10 introduced LOCcodexAgent.ts ×1codexAgent.ts ×8 · 19 introduced LOCcodexAgent.ts ×8codexAgent.ts ×158 · 1640 introduced LOCcodexAgent.ts ×158codexModelRefresh.test|title=CodexAgent model refresh keeps the last known-good models when a periodic refresh fails|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexModelRefresh.test|title=CodexAgent model refresh keeps the last known-good models when a periodic refresh fails|occurrence=1codexModelRefresh.test|t…codexPackagePaths.test|title=codex package paths codexBinaryTriple every suffix produced by codexPackageSuffix maps to a rust target triple|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths codexBinaryTriple every suffix produced by codexPackageSuffix maps to a rust target triple|occurrence=1codexPackagePaths.test|t…codexPackagePaths.test|title=codex package paths codexBinaryTriple returns undefined for unknown suffixes|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths codexBinaryTriple returns undefined for unknown suffixes|occurrence=1codexPackagePaths.test|t…codexPackagePaths.test|title=codex package paths codexPackageSuffix every supported (platform, arch) returns the npm optionalDependencies suffix|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths codexPackageSuffix every supported (platform, arch) returns the npm optionalDependencies suffix|occurrence=1codexPackagePaths.test|t…codexPackagePaths.test|title=codex package paths codexPackageSuffix never returns a -musl suffix on Linux (Codex is statically musl-linked)|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths codexPackageSuffix never returns a -musl suffix on Linux (Codex is statically musl-linked)|occurrence=1codexPackagePaths.test|t…codexPackagePaths.test|title=codex package paths codexPackageSuffix returns undefined for unsupported platforms and architectures|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths codexPackageSuffix returns undefined for unsupported platforms and architectures|occurrence=1codexPackagePaths.test|t…codex resolves|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths resolveCodexDevSdkRoot returns the directory containing node_modules when @openai/codex resolves|occurrence=1codex resolves|occurrenc…codexPackagePaths.test|title=codex package paths resolveCodexDevSdkRoot returns undefined when resolution throws (e.g. built product without the devDependency)|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths resolveCodexDevSdkRoot returns undefined when resolution throws (e.g. built product without the devDependency)|occurrence=1codexPackagePaths.test|t…codexSessionConfigKeys.test|title=codexSessionConfigKeys expands permissions presets and falls back to legacy axes|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexSessionConfigKeys.test|title=codexSessionConfigKeys expands permissions presets and falls back to legacy axes|occurrence=1codexSessionConfigKeys.t…codexSessionConfigKeys.test|title=codexSessionConfigKeys inverts presets and migrates legacy axes without escalating|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexSessionConfigKeys.test|title=codexSessionConfigKeys inverts presets and migrates legacy axes without escalating|occurrence=1codexSessionConfigKeys.t…codexSessionConfigKeys.test|title=codexSessionConfigKeys narrows valid values and rejects invalid values|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexSessionConfigKeys.test|title=codexSessionConfigKeys narrows valid values and rejects invalid values|occurrence=1codexSessionConfigKeys.t…codexSessionConfigKeys.test|title=codexSessionConfigKeys resolveSessionConfig exposes a single permissions-preset chip|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexSessionConfigKeys.test|title=codexSessionConfigKeys resolveSessionConfig exposes a single permissions-preset chip|occurrence=1codexSessionConfigKeys.t…codexSessionConfigKeys.test|title=codexSessionConfigKeys resolveSessionConfig preserves legacy read-only permissions on restore|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexSessionConfigKeys.test|title=codexSessionConfigKeys resolveSessionConfig preserves legacy read-only permissions on restore|occurrence=1codexSessionConfigKeys.t…Focused file · src/vs/platform/agentHost/common/codexSessionConfigKeys.ts · 114 LOCcommon/codexSessionConfi…

Graph controls are ready.

Interactive rendering requires JavaScript and WebGL. Use the related-file, concept, and source links on this page while the interactive map is unavailable.

1 > /*--------------------------------------------------------------------------------------------- codexAgent.ts ×158
2 > * Copyright (c) Microsoft Corporation. All rights reserved.
3 > * Licensed under the MIT License. See License.txt in the project root for license information.
4 > *--------------------------------------------------------------------------------------------*/
5 >
6 > /**
7 > * Well-known session-config keys advertised by the agent-host Codex provider
8 > * in its `resolveSessionConfig` schema.
9 > *
10 > * This file is intentionally protocol-free (no imports from the generated
11 > * `node/protocol` types) so it can be shared with the browser pickers, which
12 > * cannot import from the `node` layer. The string-literal unions below are
13 > * declared to match — and are structurally assignable to — the corresponding
14 > * generated Codex app-server types (`AskForApproval`, `SandboxMode`,
15 > * `ApprovalsReviewer`). Protocol-typed narrowing helpers live alongside the
16 > * node agent in `node/codex/codexSessionConfigKeys.ts`.
17 > */
18 > export const enum CodexSessionConfigKey {
19 > PermissionsPreset = 'codex.permissionsPreset',
20 > ApprovalPolicy = 'codex.approvalPolicy',
21 > SandboxMode = 'codex.sandboxMode',
22 > AdditionalDirectories = 'codex.additionalDirectories',
23 > NetworkAccessEnabled = 'codex.networkAccessEnabled',
24 > WebSearchMode = 'codex.webSearchMode',
25 > ModelReasoningEffort = 'codex.modelReasoningEffort',
26 > Personality = 'codex.personality',
27 > ReasoningSummary = 'codex.reasoningSummary',
28 > }
29 >
30 > /** Subset of the generated `AskForApproval` union that VS Code exposes. */
31 > export type CodexApprovalPolicy = 'never' | 'on-request' | 'on-failure' | 'untrusted';
32 >
33 > /** Mirrors the generated `SandboxMode` union. */
34 > export type CodexSandboxMode = 'read-only' | 'workspace-write' | 'danger-full-access';
35 >
36 > /** Mirrors the generated `ApprovalsReviewer` union. */
37 > export type CodexApprovalsReviewer = 'user' | 'auto_review' | 'guardian_subagent';
38 >
39 > /**
40 > * Codex collapses its three security axes (sandbox × approval policy ×
41 > * approvals reviewer) into a single user-facing "permissions" preset, matching
42 > * the selector in the Codex app and IDE extension.
43 > *
44 > * @see https://developers.openai.com/codex/concepts/sandboxing#how-you-control-it
45 > */
46 > export type CodexPermissionsPreset = 'default' | 'auto-review' | 'full-access';
47 >
48 > /** Ordered preset list advertised in the Codex session-config schema. */
49 > export const CODEX_PERMISSIONS_PRESETS: readonly CodexPermissionsPreset[] = ['default', 'auto-review', 'full-access'];
50 >
51 > /** Default preset applied to new Codex sessions. */
52 > export const CODEX_DEFAULT_PERMISSIONS_PRESET: CodexPermissionsPreset = 'default';
53 >
54 > /**
55 > * Single source of truth for narrowing an arbitrary runtime value to the
56 > * closed {@link CodexPermissionsPreset} union. Returns `undefined` for
57 > * non-strings or unmatched strings; callers apply their own fallback.
58 > */
59 > export function narrowCodexPermissionsPreset(raw: unknown): CodexPermissionsPreset | undefined {
60 > switch (raw) { codexSessionConfigKeys.ts ×6
61 > case 'default':
62 > case 'auto-review':
63 > case 'full-access':
66 > return undefined;
67 > }
68 > }
70 > export interface ICodexResolvedPermissions {
71 > readonly approvalPolicy: CodexApprovalPolicy;
72 > readonly sandboxMode: CodexSandboxMode;
73 > readonly approvalsReviewer: CodexApprovalsReviewer;
74 > }
75 >
76 > /**
77 > * Expand a {@link CodexPermissionsPreset} into the three underlying Codex
78 > * security axes sent to the app-server (`approvalPolicy`, `sandbox`,
79 > * `approvalsReviewer`).
80 > */
81 > export function resolveCodexPermissionsPreset(preset: CodexPermissionsPreset): ICodexResolvedPermissions {
82 > switch (preset) { codexSessionConfigKeys.ts ×3
83 > case 'auto-review':
84 > // Same workspace-write sandbox as `default`, but on-request approvals codexSessionConfigKeys.ts ×2
85 > // are routed through the auto-reviewer instead of a UI prompt.
86 > return { approvalPolicy: 'on-request', sandboxMode: 'workspace-write', approvalsReviewer: 'auto_review' };
87 > case 'full-access': codexSessionConfigKeys.ts ×3
88 > return { approvalPolicy: 'never', sandboxMode: 'danger-full-access', approvalsReviewer: 'user' }; codexSessionConfigKeys.ts ×2
89 > case 'default': codexSessionConfigKeys.ts ×3
90 > default:
91 > return { approvalPolicy: 'on-request', sandboxMode: 'workspace-write', approvalsReviewer: 'user' };
92 > }
93 > }
95 > /**
96 > * Inverse of {@link resolveCodexPermissionsPreset}: find the preset whose
97 > * expanded axes exactly match the given resolved permissions, or `undefined`
98 > * when no preset can represent them (e.g. a `read-only` sandbox, which no
99 > * preset expands to).
100 > *
101 > * Used when restoring a legacy session that persisted the individual security
102 > * axes but no preset: if the axes map cleanly onto a preset we can migrate them
103 > * to the modern single-preset representation; otherwise the raw axes must be
104 > * preserved so they are not silently escalated.
105 > */
106 > export function presetForResolvedPermissions(resolved: ICodexResolvedPermissions): CodexPermissionsPreset | undefined {
107 > for (const preset of CODEX_PERMISSIONS_PRESETS) { codexSessionConfigKeys.ts ×3
108 > const axes = resolveCodexPermissionsPreset(preset);
109 > if (axes.approvalPolicy === resolved.approvalPolicy && axes.sandboxMode === resolved.sandboxMode && axes.approvalsReviewer === resolved.approvalsReviewer) {
110 > return preset;
111 > }
112 > }
113 > return undefined; codexSessionConfigKeys.ts ×1
114 > }