Files
orca/src/shared
OrcaWinandOrca Worker 8d87d2cf67 feat(codex): tell Windows users once that Codex in Orca now shares ~/.codex (#24916)
* feat(codex): tell Windows users once what stays behind when Codex moves onto ~/.codex

When Windows' system-default Codex first runs on ~/.codex (launch prep or
the usage poll), main decides once whether Orca's managed home was ever
used and which MCP servers lived only there, and persists that in UI
state. The renderer shows one dismissible toast when a Codex terminal
exists, after the server-isolation notice rather than on top of it, and
clears the notice when shown.

The "kept only in the managed home" MCP rule is extracted into
isRuntimeOnlyMcpServer, which the config mirror merge now uses too, so
the notice names exactly the servers the mirror would have kept.

* fix(codex): stop counting Orca's own config.toml as use of the old Codex home

Orca's hook install writes that home's config.toml on every startup, so its
presence was true for nearly every Windows user with Codex. The home now
counts as used only with recorded sessions or an MCP server of its own.
Resolver tests keep one case per input source.

* refactor(codex): ask main for the shared-settings notice instead of persisting it

The persisted missing/object/null field, written from launch prep and the
usage poll, becomes a plain codexSharedSettingsNoticeSeen flag mirroring
codexTerminalServerIsolationNoticeSeen. When a Codex terminal first appears
and the flag is unset, the renderer asks codexConfigSync:sharedSettingsNotice
once; main answers read-only (Windows, system default on ~/.codex, managed
home path without mkdir) and maps any read error to null.

Runtime-home routing, launch and the test harness return to main's code.
The notice no longer waits for the server-isolation toast; they may stack.
The Codex-terminal watch moves to codex-terminal-presence.ts.

* refactor(codex): watch for the first Codex terminal in one place for both notices

The server-isolation notice now passes its due check to
whenCodexTerminalAppears instead of keeping its own copy of the presence
scan, input filter and subscription loop. Its behaviour and tests are
unchanged.

* docs(codex): trim isRuntimeOnlyMcpServer's comment to why it is shared

* refactor(codex): keep McpServerTomlOwnership private to its module

* test(codex): cover the shared-settings notice channel without type assertions

Handlers are looked up by channel now that two are registered, so the
status tests no longer depend on registration order.

* refactor(codex): show the Windows shared-settings notice without asking main

Every way of detecting who relied on Orca's old Codex folder had false
positives, so the renderer now shows one static toast on Windows the first
time a Codex terminal exists. This drops the main-process resolver, its IPC
channel, preload line, web stub and shared type, and the MCP-names variant
of the description.

* refactor(codex): restore the MCP server ownership helpers to main's shape

The static notice no longer reads MCP servers, so the shared
isRuntimeOnlyMcpServer extraction has no second caller.

* refactor(codex): let each notice decide when it is due, so the Codex watcher only watches

The isolation notice now selects its due predicate and starts the watcher only while due, so whenCodexTerminalAppears no longer takes an isDue or re-checks hydration and settings. The shared-settings notice uses isLocalWindowsDesktopClient, its test stubs the user agent instead of mocking pane-helpers, and the hydration safeguard it relies on is now tested on the UI slice itself.

* test(codex): drive the Codex notices through a reactive store, and drop a redundant hydration gate

The server-isolation notice now reads "is it due" through a store selector, but its test
mocked the store without re-rendering, so a due change after mount (persisted UI loading,
the setting turning off) was never exercised. The notice tests now share one harness backed
by a real zustand store, the shared watcher gets its own test, and both notices cover the
seen flag loading after mount.

persistedUIReady is dropped from isNoticeDue: the seen flag defaults to true and only
hydration clears it, in the same update that sets persistedUIReady. Both notices now gate
the same way.

* fix(codex): keep the shared-settings toast until dismissed, and shorten it

It is marked seen before it shows, so a 15s auto-close could lose it for good while the user
is typing in the Codex terminal that triggered it. Every other one-shot notice that marks
itself seen on show stays until dismissed; this now does too.

The text drops the sentence that repeated the title and keeps only what to expect and do.

---------

Co-authored-by: Orca Worker <orca-worker@localhost>
2026-10-04 11:19:02 -07:00
..
2026-09-03 17:32:59 -07:00