Skip to content

disallow fileparams metadata for custom mcps#19836

Open
colby-oai wants to merge 4 commits intomainfrom
codex/disallow-fileparams-for-non-connectors
Open

disallow fileparams metadata for custom mcps#19836
colby-oai wants to merge 4 commits intomainfrom
codex/disallow-fileparams-for-non-connectors

Conversation

@colby-oai
Copy link
Copy Markdown
Contributor

@colby-oai colby-oai commented Apr 27, 2026

Summary

Disallow fileParams metadata for custom MCPs

Restricts Codex openai/fileParams handling to the first-party codex_apps MCP server. Custom MCP servers may still advertise the metadata, but Codex now ignores it for upload rewriting, preventing non-Apps tools from receiving signed OpenAI file refs for local paths. Added a regression test for the allowed and denied cases.

@colby-oai colby-oai requested a review from a team as a code owner April 27, 2026 17:22
Comment thread codex-rs/core/src/mcp_tool_call.rs
Comment thread codex-rs/core/src/mcp_tool_call.rs
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants