Tyxy-R
codex-referral-risk-research
Research tooling for evaluating SSO referral-flow abuse resistance, quota behavior, and activation telemetry in authorized test environments.
Documentation snapshot
README 快照
翻译暂时拿不到。
机器翻译的项目简介,仅供参考。原文在下方,也可以直接用浏览器自带的整页翻译 (Chrome / Edge 点地址栏右侧的翻译图标,或用右键菜单里的「翻译成中文」)。
下面正文是项目自己的英文 README。想读全文就用浏览器自带的整页翻译: Chrome / Edge 点地址栏右侧的翻译图标,或用右键菜单里的「翻译成中文」; 手机浏览器一般在菜单里。
本页保存的是公开项目资料快照,阅读过程不需要连接 GitHub。
Codex Referral Risk Research
This repository contains research tooling for studying SSO-based workspace referral flows, invite quota behavior, token lifecycle handling, and activation telemetry patterns in a controlled anti-fraud research setting.
The project is intended to help security and risk teams reproduce referral-flow edge cases, measure concurrency behavior, and evaluate where abuse-resistant controls should be enforced.
Companion Repository
This repository is companion tooling for:
https://github.com/Tyxy-R/chatgpt-sso-keycloak
Use this project after the Keycloak SAML IdP is deployed and the target email domain is verified in the OpenAI Workspace.
Research Focus
- SSO account creation paths in OAuth-based product onboarding.
- Workspace referral quota enforcement under concurrent invitation attempts.
- Differences between user-level and workspace-level referral limits.
- Token refresh and account activation behavior after referral acceptance.
- Batch-flow observability for fraud-risk analysis and control validation.
Repository Contents
-
codex_protocol_login.py
Direct Codex OAuth + SSO login flow. Supports single-account and CSV batch modes. -
codex_invitation_helper.py
Single-account referral quota probing and invite request helper. -
codex_invitation_batch.py
Concurrent seed-account invitation runner for quota and race-condition research. -
codex_activation_helper.py
Single-account protocol activation simulator. -
codex_activation_batch.py
Concurrent activation runner for invited-account research. -
sentinel.py,sentinel_quickjs.py,openai_sentinel_quickjs.js
Sentinel token generation helpers used by the login flow. -
codex_sso_login.py
Browser-based fallback login helper.
Data Safety
Runtime data is intentionally excluded from git. Do not commit:
- account auth files
- access tokens
- refresh tokens
- id tokens
- account IDs
- real email/password CSV files
- invite result exports
- local logs
The .gitignore blocks common runtime directories and sensitive file patterns such as:
accounts/runs/*.csv*auth*.json.venv/*.log
Only sanitized examples should be committed under examples/.
Setup
python3 -m venv .venv
.venv/bin/pip install -r requirements.txt
Example Research Workflow
Create a local CSV in the format shown by examples/accounts.example.csv:
user1@example.com,YourPassword
user2@example.com,YourPassword
Log in seed accounts:
.venv/bin/python codex_protocol_login.py \
--csv runs/example/seed_accounts.csv \
--out-dir runs/example/seeds \
--proxy http://127.0.0.1:PORT \
--concurrency 10 \
--retries 2 \
--skip-existing
Probe and send referral invites from seed accounts:
.venv/bin/python codex_invitation_batch.py \
--auth-dir runs/example/seeds \
--domain example.com \
--per-account 5 \
--proxy http://127.0.0.1:PORT \
--save-back \
--out runs/example/invite_results.json
Extract only successfully invited emails:
jq -r '.[].invites[]?.email | . + ",YourPassword"' \
runs/example/invite_results.json > runs/example/invitee_accounts.csv
Log in invited accounts:
.venv/bin/python codex_protocol_login.py \
--csv runs/example/invitee_accounts.csv \
--out-dir runs/example/invitees \
--proxy http://127.0.0.1:PORT \
--concurrency 10 \
--retries 2 \
--skip-existing
Run activation telemetry simulation:
.venv/bin/python codex_activation_batch.py \
--auth-dir runs/example/invitees \
--proxy http://127.0.0.1:PORT \
--save-back
Notes for Researchers
- Treat all generated auth files and CSVs as sensitive.
- Use isolated research tenants and domains.
- Validate results from server responses, not only from locally generated inputs.
- For invite analysis, count only
invites[].emailentries returned by the service. - Keep raw artifacts under ignored runtime directories such as
runs/.
License
MIT License. See LICENSE.
Star History
Official distribution
获取与安装
暂未发现可确认的官方软件包地址
当前 README 快照没有出现 npm、PyPI、Crates.io、pub.dev 等官方包页链接。本站不会根据仓库名称猜测下载地址。
本站不托管项目文件;需要安装时,请以项目维护者发布的官方文档为准。
Before installing
使用前核验
本站保存公开资料用于阅读,不代表安全审计或功能背书。安装前请核对许可证、依赖来源和发布签名,不要直接运行来源不明的二进制文件或高权限脚本。