Manual QA checklist for the interactive auth dashboard (lib/ui/auth-menu.ts, lib/cli.ts) and the quota status surface (tui.ts). Run through it before releases that touch the auth menu, account actions, or quota display — the items below mirror the live code, so a drift here is a real regression.
opencode auth login on a TTY opens the account dashboard (showAuthMenu); non-TTY falls back to a readline menu ((a)dd, (f)resh, (c)heck, (d)eep, (v)erify flagged, or (q)uit), and non-interactive mode defaults to add.
- Sections render in order:
Actions,Accounts,Danger zone. - Actions, in order:
Add account,Check quotas,Deep check accounts,Verify flagged accounts(suffixed with the flagged count when non-zero),Start fresh, thenDelete all accountsunder Danger zone. - Each account row shows: numeric index, email (masked when
maskEmail),workspace:<label>,id:/seat:suffixes when present, state badge, and aused <relative time>hint.
statusBadge renders [active]/[ok] (success), [rate-limited]/[cooldown] (warning), [flagged]/[disabled]/[error] (danger); [current] marks the serving account. V2 styling (codexTuiV2, default on) paints the same badges through formatUiBadge instead of raw ANSI.
- Up/Down moves selection; Enter confirms; Esc backs out; Ctrl+C exits without corrupting terminal state; cursor visibility is restored on exit.
- Selecting an account opens the detail menu:
Back,Enable/Disable account(label flips with state),Refresh account,Delete this account. - Destructive actions confirm first:
Delete all accountsandStart freshboth require typingDELETEat theType DELETE to confirm removing all accounts:prompt.
Check quotasiterates enabled accounts printing[i/N] <label>: <status>lines (OK,OK (cached access),OK (Codex CLI cache),DISABLED,ERROR (<reason>)), then a summary count line.Deep check accountsperforms stricter per-account validation with richer diagnostic output on the same[i/N]progress format.Verify flagged accountsre-probes flagged entries and prints[i/N] <label>: RESTOREDorSTILL FLAGGED (<reason>).
- Disabled accounts stay visible in the dashboard but are skipped by rotation and by health-check iteration.
- Accounts whose refresh token is rejected move to flagged storage beside the active pool file;
Verify flagged accountsrestores ones that refresh successfully. - Deleting clears both the active pool and flagged state for that account.
codexTuiV2/CODEX_TUI_V2(default on) selects the V2-styled menu;0/falsefalls back to the legacy look.codexTuiColorProfile:truecolor(default) /ansi256/ansi16.codexTuiGlyphMode:ascii(default) /unicode/auto.maskEmail: true/CODEX_TUI_MASK_EMAIL=1masks the account email on every human-facing surface — auth menu,codex-list/codex-status/codex-limits/codex-health/codex-dashboard, runtime/log messages, standalone CLI login menu, and the prompt quota line. A user-defined account label wins over the email where one exists.maskEmailInQuotaDetails: true/CODEX_TUI_MASK_EMAIL_DETAILS=1additionally masks the quota details view. Shared helpers live inlib/account-display.ts— new surfaces must route through them.
quotaStatus.modeselectsactive,overview,resets, or a list rotated everyrotateMs; empty screens are skipped,resetsappears only atresetsMinUsedPercent(default 100) weighted usage.- The prompt slot width is measured from the rendered row (
measureStatusSlot), so an open sidebar shrinks the line correctly;rows(1–4, default 1) is a ceiling, not a measurement. - Quota percentages use the shared
quotaDisplayfree/used wording across the TUI,codex-limits, the standalone CLI, and notifications.
-
npm run typecheckandnpm testpass - Login → dashboard appears with Actions / Accounts / Danger zone
- Add account completes an OAuth round trip into the pool
- Check quotas prints
[i/N]lines and a summary - Disable account removes it from rotation candidates
- Verify flagged restores a recoverable account
- Delete-all requires typed
DELETEand clears active + flagged pools -
maskEmailon → no raw email anywhere -
codexTuiV2off → legacy menu still works