Skip to content

Allow Windows users to run Codex in "no sandbox" mode and explicitly approve/deny commands #18005

@rwalle

Description

@rwalle

What variant of Codex are you using?

CLI

What feature would you like to see?

Currently, for Windows users, whenever they use Codex with any new folder (workspace), they will be greeted with the sandbox setup screen and have to choose between default sandbox, non-admin sandbox or quit.

Image

We would like another "no sandbox" option where user explicitly approves/denies commands.

Additional information

The default sandbox is not allowed by IT (due to concerns documented in #12343 and elsewhere), while non-admin sandbox carries significant risk and allows running arbitrary command without approval in our testing.

We do notice that if user chooses "quit" and immediate open codex again for the same folder, they can use Codex in a mode where they explicitly approve/deny any potentially risky command. There is no sandbox being applied in this mode.

Could Codex make this "no sandbox" mode an explicit choice in that screen?

Metadata

Metadata

Assignees

No one assigned

    Labels

    CLIIssues related to the Codex CLIenhancementNew feature or requestsandboxIssues related to permissions or sandboxingwindows-osIssues related to Codex on Windows systems

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions