Skip to content

Preserve profile architecture proposals - #20

Open
brettheap wants to merge 1 commit into
mainfrom
docs/profile-architecture-recovery-20260909
Open

brettheap wants to merge 1 commit into
mainfrom
docs/profile-architecture-recovery-20260909

Conversation

@brettheap

@brettheap brettheap commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Rebases four local profile-management architecture proposals onto the current broker-enabled main branch and links them from the README. The machine-local Azure deployment plan remains outside Git.\n\nValidation:\n- repository-pinned Prettier passes for all five touched Markdown files\n- linked documents exist\n- credential, private-key, SSN-shape, and non-placeholder email scan is clean

Summary by Sourcery

Preserve and publish the proposed profile-management architectures for future implementation.

New Features:

  • Add four proposed profile-management architecture documents covering Codex identity and history profiles, Codex credential synchronization, cloud credential brokering, and Claude OAuth enrollment.
  • Link the proposed architecture documents from the README.

Documentation:

  • Document secure credential storage, refresh ownership, profile/history isolation, provider enrollment, synchronization, recovery, and delivery plans for future implementation.

Chores:

  • Preserve the machine-local Azure deployment plan outside the repository.

Copilot AI lite review requested due to automatic review settings September 9, 2026 17:09

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @brettheap, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 1 day and 10 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@brettheap

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@sourcery-ai

sourcery-ai Bot commented Sep 9, 2026

Copy link
Copy Markdown

Reviewer's Guide

Preserves four rebased, security-focused profile-management architecture proposals and makes them discoverable from the README; the Azure deployment plan remains intentionally outside the repository.

Sequence diagram for single-owner credential rotation

sequenceDiagram
    participant Runtime as Provider_Runtime
    participant Broker as Credential_Broker
    participant Vault as Azure_Key_Vault
    participant Mirror as Dormant_Profile

    Runtime->>Broker: acquire_lease
    Broker-->>Runtime: lease_id_and_epoch
    Runtime->>Runtime: Replace_credential_file
    Runtime->>Broker: publish
    Broker->>Broker: Validate_identity_and_generation
    Broker->>Vault: Write_new_secret_version
    Broker->>Broker: Advance_accepted_generation
    Broker->>Mirror: Update_dormant_checkout
    Broker-->>Runtime: Publication_accepted
Loading

State diagram for credential ownership and recovery

stateDiagram-v2
    [*] --> idle
    idle --> owner : checkout
    owner --> publishing : rotation
    publishing --> idle : publish_accepted
    owner --> reconciling : release
    reconciling --> idle : release_complete
    owner --> conflict : unowned_divergence
    owner --> recovery_required : interrupted_operation
    conflict --> recovery_required : ownership_uncertain
    recovery_required --> idle : fresh_login
Loading

File-Level Changes

Change Details Files
Adds four proposed profile-management architecture documents covering Codex history/identity separation, Codex credential synchronization, cloud credential brokering, and Claude OAuth enrollment.
  • Defines app-server-based Codex history/runtime bindings and opaque JSONL transfer workflows.
  • Defines single-writer refresh leases, complete credential generations, atomic synchronization, and conflict recovery for Codex.
  • Defines Entra-authenticated broker, versioned Azure Key Vault storage, cross-runtime leases, and staged reauthentication.
  • Defines authorized Claude CLI orchestration with scoped mailbox access, isolated browser automation, identity validation, and secret-handling boundaries.
docs/codex-history-profile-architecture.md
docs/codex-token-management-architecture.md
docs/cloud-credential-vault-feature.md
docs/claude-oauth-enrollment-automation.md
Links the proposed architecture documents from the repository README.
  • Adds a dedicated profile-management designs section with links to all four proposals.
README.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sonarqubecloud

sonarqubecloud Bot commented Sep 9, 2026

Copy link
Copy Markdown

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The changes are documentation-only additions with valid local links and no functional/code-path impact.

Pull request overview

This PR preserves and publishes four proposed profile-management architecture documents (Codex identity/history isolation, Codex credential rotation/sync, a cloud credential vault/broker, and Claude OAuth enrollment automation) and links them from the README so they’re discoverable for future implementation work.

Changes:

  • Add four new “Status: proposed” architecture/design documents under docs/.
  • Link the new proposal documents from the README.
File summaries
File Description
README.md Adds a small index of the new proposed profile-management design docs.
docs/codex-history-profile-architecture.md Proposal for separating identity vs history profiles via runtime bindings and Codex app-server APIs.
docs/codex-token-management-architecture.md Proposal for single-writer refresh ownership and safe Windows/WSL credential synchronization.
docs/cloud-credential-vault-feature.md Proposal for a remote credential authority using Azure Key Vault plus a brokered lease model.
docs/claude-oauth-enrollment-automation.md Proposal for Claude CLI-based enrollment/reauth flows with mailbox + Playwright automation under strict safety constraints.
Review details
  • Files reviewed: 5/5 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants