Skip to content

feat: prepare uploads.sh for the OpenAI plugin directory - #1059

Draft
Zach Dunn (zachdunn) wants to merge 1 commit into
mainfrom
codex/openai-directory
Draft

Zach Dunn (zachdunn) wants to merge 1 commit into
mainfrom
codex/openai-directory

Conversation

@zachdunn

Copy link
Copy Markdown
Member

In plain terms

Prepare uploads.sh for submission to the OpenAI plugin directory by reusing the existing skills, branding, hosted MCP server, and Claude review cases. This adds a repeatable directory ZIP build and the optional identity scopes OpenAI needs for verified-email checks. Both free and paid uploads.sh accounts can connect.

What it does / what it is not

  • Builds a portable plugin ZIP containing the hosted MCP configuration, three shared skills, and logo. Local hooks, Claude mods, and repository files stay outside the public package.
  • Enables optional openid and email scopes, OIDC discovery, and Better Auth's UserInfo endpoint. Email verification reflects the user's actual status; identity-only tokens do not receive workspace membership or file authority.
  • Adds reusable review cases, public PNG fixture inputs, recording import, a submission runbook, CI package checks, and a plugin changeset.
  • Prepares a draft package. It does not deploy workers, submit to OpenAI, or publish a directory listing. Live OpenAI OAuth and attachment tests still need the reviewer fixtures and recording.

How to try it

In this repository, run pnpm plugin-directory:check and pnpm plugin-directory:build. The draft ZIP is written to dist/plugins/uploads-openai-<plugin-version>.zip.

To import reviewer fixture details and a recording, follow plugins/codex/directory.md and build with --review-config /absolute/path/to/review.json. Keep reviewer credentials in the portal's private Review details.

Technical notes

Existing OAuth clients keep their persisted scope ceilings and existing tokens keep their grants. Use a fresh OpenAI client registration to request identity scopes. email requires requested, permitted openid; the server does not add identity scopes implicitly. No migrations, dependency patches, or environment-file edits are required.

The consent labels were checked with synthetic local account data. The screenshot is staged for this branch and will be promoted to the managed attachments comment.

Test plan

  • Full auth suite: 36 files, 494 tests passed.
  • Packaging boundary tests: four passed; ZIP integrity and allowlisted contents verified.
  • Auth and web typechecks; generated Wrangler types for all workers.
  • Repository lint and formatting; plugin version, skill parity, changeset, and diff checks.
  • Consent UI preview with synthetic data; screenshot captured and staged.
  • Independent review of packaging and OAuth scope boundaries; findings resolved.
  • Deploy auth and consent changes, connect a fresh OpenAI OAuth client, and verify discovery, consent, refresh, and UserInfo through the portal.
  • Run the five positive and three negative cases in OpenAI with the dedicated reviewer account and fixtures, including a real ChatGPT attachment.
  • Supply the recording, complete domain verification and automated scans, and submit the draft for review.

@changeset-bot

changeset-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4bb42f8

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@uploads/plugin Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are limited based on label configuration.

🏷️ Required labels (at least one) (2)
  • coderabbit:review
  • review
🚫 Excluded labels (none allowed) (1)
  • wip

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 056b2688-eec9-4e7d-b37c-3ccec865dcf4

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@uploads-sh

uploads-sh Bot commented Oct 3, 2026

Copy link
Copy Markdown

consent-identity-after.webp
/oauth/consent · after

Maintained by uploads.sh · add media: uploads put <file> --pr 1059 · docs

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
uploads-auth 4bb42f8 Oct 03 2026, 01:09 AM

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
uploads-web 4bb42f8 Commit Preview URL

Branch Preview URL
Oct 03 2026, 01:09 AM

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant