[codex] Gate remote plugin catalog by auth (#28625)

## Summary

- Treat the remote global plugin catalog as active only when
`remote_plugin` is enabled and the current auth uses the Codex backend.
- Skip the local OpenAI curated marketplace for remote-enabled ChatGPT
users while preserving configured marketplaces.
- Keep the local curated marketplace for API-key users, unauthenticated
fallback, and ChatGPT users with `remote_plugin` disabled.
- Apply the same effective-remote gate to the remote
installed-marketplace cache.

## Root cause

The tool-suggestion discovery path unconditionally included the local
OpenAI curated marketplace. For remote-enabled ChatGPT users, that made
remote discovery additive: Codex parsed every local curated
`plugin.json` before also loading the remote catalog.

## Validation

- `just fmt`
- `cargo build -p codex-cli --bin codex`
- Targeted auth/feature matrix tests pass, including API-key auth with
`remote_plugin` enabled.
- Manual CLI validation confirmed:
  - ChatGPT + remote off includes local curated.
  - ChatGPT + remote on excludes local curated.
  - API-key auth keeps local curated when remote is enabled.
- `just test -p codex-core-plugins`: 235 passed; one unrelated existing
marketplace test failed because it loaded the developer's home
marketplace configuration.
This commit is contained in:
xl-openai
2026-06-16 17:24:48 -07:00
committed by GitHub
Unverified
parent bfe90188ad
commit 69bc0645ac
2 changed files with 45 additions and 10 deletions
+8 -2
View File
@@ -76,11 +76,17 @@ impl PluginsManager {
return Ok(Vec::new());
}
let use_remote_global_catalog =
input.plugins.remote_plugin_enabled && auth.is_some_and(CodexAuth::uses_codex_backend);
let marketplaces = self
.list_marketplaces_for_config(&input.plugins, &[], /*include_openai_curated*/ true)
.list_marketplaces_for_config(
&input.plugins,
&[],
/*include_openai_curated*/ !use_remote_global_catalog,
)
.context("failed to list plugin marketplaces for tool suggestions")?
.marketplaces;
let remote_installed_marketplaces = if input.plugins.remote_plugin_enabled {
let remote_installed_marketplaces = if use_remote_global_catalog {
self.build_remote_installed_plugin_marketplaces_from_cache(&[
REMOTE_GLOBAL_MARKETPLACE_NAME,
])