Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion PRIVACY.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,8 @@ Codex Desktop, its local app-server, Claude Code, and Anthropic's API remain gov

Optional Codex account management reads local Codex `auth.json` for explicit registration, switching, and identity checks while refreshing registered-account usage. Replacement happens only on an explicit switch. Additional accounts use official Codex browser login in a restricted temporary home; temporary credentials are removed after import or cancellation. The separate account vault and recovery transaction are DPAPI encrypted and ACL restricted to the Windows user; the login staging directory also permits SYSTEM. They are never sent to this project's developers. DPAPI protects data at rest; it does not protect against other software already running as the same Windows user. The active Codex credential remains owned by the live authentication file: saved snapshots never override its newer tokens during recovery. Uninstall intentionally preserves the separate account vault to avoid losing saved logins.

An explicit **사용량 조회** request for an inactive account temporarily places that account's credential in a separate, user-only private home for the official local app-server. It never replaces the active login. The helper may refresh authentication while reading usage; after its confirmed exit, updated credentials are atomically saved back to the DPAPI vault even on request failure or cancellation. A DPAPI recovery journal retains the selected commit credentials before the vault write, including recovery interrupted by another crash. Temporary plaintext files are removed after verified persistence. An interruption before credential commit retains staging and requires **중단된 조회 복구** after Codex writers stop. If only post-commit file cleanup remains, **임시 파일 정리** can retry while Codex stays open without modifying authentication or the vault. A failed cleanup retains only a safe error category and numeric code in the encrypted journal; raw exception text and paths are not logged. Each account retains only its latest successful percentages, reset times, and check time; the application does not attribute usage to people or retain a usage timeline.
A usage read, triggered once by opening a new account manager window or explicitly through **전체 갱신** / **이 계정 사용량 조회**, for an inactive account temporarily places that account's credential in a separate, user-only private home for the official local app-server. It never replaces the active login. The helper may refresh authentication while reading usage; after its confirmed exit, updated credentials are atomically saved back to the DPAPI vault even on request failure or cancellation. A DPAPI recovery journal retains the selected commit credentials before the vault write, including recovery interrupted by another crash. Temporary plaintext files are removed after verified persistence. An interruption before credential commit retains staging and requires **중단된 조회 복구** after Codex writers stop. If only post-commit file cleanup remains, **임시 파일 정리** can retry while Codex stays open without modifying authentication or the vault. A failed cleanup retains only a safe error category and numeric code in the encrypted journal; raw exception text and paths are not logged. Each account retains only its latest successful percentages, reset times, and check time; the application does not attribute usage to people or retain a usage timeline.

The combined manager observation set exists only in memory and stays separate from automatic active-account polling. It contains no additional credential copy or usage history. Full queries run sequentially and stop when credential recovery or temporary-file cleanup requires attention.

When reporting a bug, do not attach Codex or Claude logs, credential/configuration files, tokens, or screenshots containing information you do not want to publish.
16 changes: 11 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,17 +23,23 @@ Account management is optional. After you register a Codex account, the widget s

## Manual Codex accounts

Open **Codex 계정 관리…** from the right-click menu, or double-click the tray icon. Choose **현재 계정 등록** to save the current login with a unique default name. Select an account in the left list to view its status and usage; use **이름 변경** or F2 to edit its name. Enter saves and Escape cancels. Account names appear only in the manager; the compact indicator shows percentages and bars. Renaming only changes local metadata and does not restart the usage helper. If you sign into an unregistered account directly in Codex, the manager offers registration above the existing list.
Open **Codex 계정 관리…** from the widget menu, or double-click the tray icon. The light-themed manager uses one overview and one account list, sorted by the nearest weekly reset. Its default height fits three accounts without scrolling on a sufficiently tall display. Account names appear in the manager and hover details; the compact indicator remains percentages and bars. Hover details separate the current account, the last combined observation with each account reset, and Claude. Hover never requests usage; the combined observation remains available after closing the manager and lasts for the widget process.

Choose **+ 다른 계정 추가**, optionally name the account, then select **브라우저에서 로그인**. Complete the official browser login using the additional account. This login uses an isolated private `CODEX_HOME` and does not log the desktop out; **로그인 취소** stops only the login process owned by this tool. The widget maintains its topmost position without activating itself, including when it reappears, so typing in the manager or another app keeps focus.
The overview adds the remaining weekly percentages: for example, **168% of 300%** across three accounts. Each account contributes up to 100%; this is an unweighted sum of account percentages, not a shared service limit or a comparison of different plans' absolute quotas. **다음 초기화** identifies the next confirmed reset and that account's remaining amount. The latest reset appears as secondary context; it is not a common deadline for the whole total.

Select the saved account and click **이 계정으로 전환**. The preparation dialog shows the source and target names and waits while you finish your work and close Codex Desktop and other Codex CLI/engine processes. **전환하고 Codex 열기** becomes available when they have stopped; cancellation keeps the current login. The widget stops its own usage helper, verifies once more that no Codex writers remain, saves the latest current login, and applies the selected login. It attempts to reopen the previously observed packaged desktop; if necessary, launch Codex from the Start menu and confirm the account there. File application and desktop login verification are separate outcomes.
Opening a new manager window starts one sequential usage query for all registered accounts. After that, **전체 갱신** is the only way to refresh the whole observation set. Restoring focus, changing selection, the local five-second UI timer, and the active widget's own polling do not trigger another batch or change this snapshot. Closing the window during a batch cancels the request and waits for safe cleanup. Failure, cancellation, missing/expired weekly data, or changed membership withholds the total and distinguishes the confirmed subtotal from previous values. Cleanup or credential recovery stops the remaining batch.

Select any registered account and click **사용량 조회** to fetch its latest weekly and 5-hour remaining usage, reset times, and last successful check time. **목록 갱신** only reloads saved values. Inactive accounts are queried only on an explicit click, using a short-lived official app-server in a private isolated home. Codex Desktop and the current account stay signed in; the current widget helper is not suspended. Active-account queries reuse that helper and require Codex Desktop to be open. **조회 취소**, a timeout, or a failed request preserves the last successful usage observation. Refreshed credentials are saved even if the usage request fails or is canceled. Expired logins can be renewed through **+ 다른 계정 추가** using the same inactive account; for the active account, sign in again in Codex.
Choose **현재 계정 등록** to save the current login with a default name. The **···** menu on each account contains **이름 변경**, **이 계정 사용량 조회**, **상세 정보**, and **저장된 로그인 삭제**. Enter saves a name and Escape cancels. Renaming only changes local metadata. The detail dialog contains the masked identity and latest 5-hour observation. An individual usage read updates that row and marks the overall total for a new full refresh; other observations retain their check times, while the total requires a full refresh so separate checks cannot silently masquerade as one complete batch. A background active-account poll does not alter the manager's observation set.

Choose **+ 계정 추가**, optionally name the account, then select **브라우저에서 로그인**. Complete the official browser login using the additional account. This login uses an isolated private `CODEX_HOME` and does not log the desktop out; **로그인 취소** stops only the login process owned by this tool. If you sign into an unregistered account directly in Codex, the manager offers registration above the list.

Click **전환** on the desired account. The preparation dialog shows the source and target names and waits while you finish your work and close Codex Desktop and other Codex CLI/engine processes. **전환하고 Codex 열기** becomes available when they have stopped; cancellation keeps the current login. The widget suspends its own helper, checks for remaining writers, preserves the latest current login and applies the selected login, then attempts to reopen Codex. Confirm the account there; file application and desktop login verification are separate outcomes. The widget's show/re-show and topmost maintenance preserve keyboard focus in other apps.

Inactive usage reads use a short-lived official app-server in a private isolated home. Codex Desktop and the current account stay signed in, and the current helper is not suspended. Active-account reads reuse that helper and require Codex Desktop to be open. A timeout, cancellation or failed request preserves the last successful observation; refreshed credentials are saved even when usage retrieval fails. Expired inactive logins can be renewed through **+ 계정 추가** with that same account; renew the active login in Codex. The manager's background context menu can reload the saved account list without requesting usage.

Only explicit selections cause a switch. There is no automatic quota rotation, proxy, inactive-account background polling, quota pooling, usage history, or per-person attribution. Values past their reset time are marked **갱신 필요**. A pending switch transaction blocks polling until **미완료 전환 복구** reconciles it with actual live authentication. A query interrupted before credentials are safely saved offers **중단된 조회 복구**; finish Codex work and close remaining Codex writers before this exceptional recovery. Its encrypted journal preserves refreshed credentials before staging is removed. Recovery never overwrites newer live authentication.

If credentials are already saved and only temporary files remain, the manager instead shows **임시 파일 정리 대기** with an **임시 파일 정리** button. This cleanup can run while Codex stays open and does not block account editing or switching. The next inactive usage request also retries cleanup before starting. A temporary file lock is retried automatically; a persistent failure displays its category and code. Cleanup does not turn a failed or canceled usage request into a success, and periodic list refresh preserves the original result. The management window supports display scaling, and its details scroll when the window is made smaller.
If credentials are already saved and only temporary files remain, the manager instead shows **임시 파일 정리 대기** with an **임시 파일 정리** button. This cleanup can run while Codex stays open and does not block account editing or switching. The next inactive usage request also retries cleanup before starting. A temporary file lock is retried automatically; a persistent failure displays its category and code. Cleanup does not turn a failed or canceled usage request into a success, and periodic list refresh preserves the original result. The management window supports display scaling, and its account list scrolls when the window is made smaller.

The first version supports local Windows file-based ChatGPT authentication. Unsupported keyring/managed configurations fail closed. The vault is stored separately at `%LOCALAPPDATA%\CodexWeeklyUsageIndicator.Accounts`; uninstall preserves it. Delete inactive accounts from the manager before removing the app if you no longer want their saved credentials. This convenience tool does not establish that any particular multi-account usage pattern is permitted by the service terms.

Expand Down
24 changes: 24 additions & 0 deletions docs/combined-usage-delivery.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
# Account overview and light interface — 1.7.0

The account manager now has one light overview and one account list, ordered by weekly reset. The user rejected the additive two-pane layout, requested a light palette and readable multi-account hover details, and asked for three accounts to fit when the window opens. Default size is 920 × 740 logical pixels, bounded by the available screen. Small windows retain scrolling.

## Behavior

- Each newly opened manager runs one sequential full query. Refocusing the same window, selection, local UI timers and hovering do not query inactive accounts. The full refresh button explicitly repeats the batch.
- The overview sums percentages without averaging: three accounts at 63%, 81%, and 24% show 168% out of 300%. Each account contributes a 100% unit; different plans are not normalized to a common token quota. Account switching remains explicit.
- A complete total requires a successful, newly persisted observation for every member, a seven-day window, future reset times, and unchanged account membership. Failures and cancellations retain prior observations with timestamps. An uncertain earlier reset prevents the header from claiming that another confirmed account is the next reset. The latest reset is context, not a common expiry deadline.
- One-account queries preserve other observations but withhold the total until the next full batch. Metadata updates preserve usage values. Active widget polling never changes the manager observation set.
- The widget retains that in-memory observation set after the manager closes. Its light, non-activating hover window separates current Codex usage, all saved accounts and their reset schedule, and Claude. Up to five accounts are listed before a link hint to the manager. There is no added usage-history file.
- A batch aborts remaining requests when credentials need recovery or temporary files still need cleanup. Closing an in-flight batch requests cancellation and waits for safe cleanup before closing the window. The existing encrypted vault and authentication transaction paths are retained.

## Validation and review

The required release build passes 29 regression groups, including native manager registration/rename/focus, manual usage failure/cancellation/cleanup, aggregate coverage/reset boundaries, sequential batches, duplicate suppression, no-op persistence rejection, close cancellation, tooltip freshness boundaries and the native tooltip's non-activating layout. Synthetic UI captures at the target 175% DPI cover normal, partial, in-flight and small-window states. The three-account default layout is asserted to have no vertical scrollbar.

An explicit opt-in live batch uses the production widget callback. Every registered account receives a new observation while the active authentication bytes remain unchanged, Codex Desktop stays running, no active-helper suspension occurs, and no query staging or journal remains. This is an integration check; it is not a claim that the user personally accepted every new screen.

Actual Claude Fable reviews examined the aggregate contract and implementation. Adopted findings include validating persistence time before certifying success, preserving actionable failures and previous observation times, handling an uncertain earlier reset, and stopping unresolved cleanup before querying further accounts. Individual queries deliberately do not certify a mixed observation set; this follows the requested full-refresh boundary.

## Delivery

The Windows artifact is built and tested by GitHub Actions. Verify the draft release checksums, ZIP manifest, binary version and absence of private build paths before installing through the existing interactive per-user scheduled-task installer. Verify the installed binary and supervisor/widget pair, then publish the verified draft. No vault schema migration is required. Resolve pending account recovery before rollback.
Loading