Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 0 additions & 12 deletions .changeset/codex-cli-login.md

This file was deleted.

12 changes: 0 additions & 12 deletions .changeset/plan-file-escape-hatch.md

This file was deleted.

22 changes: 22 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,27 @@
# @planningo/duul

## 1.1.0

### Minor Changes

- 19b5420: Support Codex CLI login for the `openai` provider β€” no `OPENAI_API_KEY` required.

When no `OPENAI_API_KEY` (or per-request `api_key`) is set, DUUL now falls back to the OpenAI Codex CLI credentials in `~/.codex/auth.json` (override with `CODEX_HOME`):

- **Sign in with ChatGPT:** uses the OAuth access token against the ChatGPT backend Responses endpoint (`https://chatgpt.com/backend-api/codex`), billed to your ChatGPT plan. Tokens are refreshed automatically via the OAuth endpoint (on expiry and on a mid-review 401).
- **API-key login:** uses the `OPENAI_API_KEY` stored in `auth.json`.

The ChatGPT backend is stateless (`store: false`): DUUL streams the request, aggregates output items from the stream, resends the full input (echoing encrypted reasoning) across tool rounds, and drops unsupported params (`temperature`, `top_p`, `max_output_tokens`, `previous_response_id`). Cross-round context is preserved by replaying prior rounds' turns (new `conversationReplay` provider capability, same mechanism as the Anthropic provider), so `previous_review_id` continuity works. Add `DUUL_REASONING_EFFORT` (default `medium`) to tune reasoning effort. An explicit env/request key always takes precedence over the CLI login.

- 7a6123f: Fix the recurring `-32602: plan required` (and `code`/`approved_plan` equivalents) failure where a caller's tool call collapsed to an empty `{}` and looped.

Two-part fix:

- **Reachable guards.** The large required string fields (`plan`, `code`, `approved_plan`) are now `optional` at the schema level, so an empty/partial call reaches the handler instead of being rejected pre-handler by the MCP SDK. Callers now get actionable retry guidance instead of an opaque `-32602` zod error. (Partition's short `workspace_root` was also relaxed to `optional` for the same reachability reason β€” the handler still hard-requires it.)
- **File escape hatch.** Added `plan_file` (plan review), `code_file` + `approved_plan_file` (code review), and `approved_plan_file` (execution partition). Callers can write large content to a file with a normal Write call and pass a short relative path; the server reads it (scoped, symlink-guarded, `tracked_only` bypassed for the caller's own artifact). This avoids the large-argument serialization failure that made models emit `{}`.

The reviewer system prompts now emit free-text fields in compressed style to reduce output tokens. Exactly one of the inline field or its `*_file` companion is required.

## 1.0.1

### Patch Changes
Expand Down
2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@planningo/duul",
"version": "1.0.1",
"version": "1.1.0",
"description": "DUUL β€” Dual-phase Upfront-plan & Unit-verify Loop. MCP server for LLM peer review of plans and code.",
"type": "module",
"main": "build/index.js",
Expand Down