Why the email path needs a human check
Codex is OpenAI’s coding agent. You can use it from the terminal, from your editor, or hand it tasks to work on in the cloud and review the result. It’s good at the code around authentication: forms, API routes, token handling and templates.
But a change can pass every test and still send an email that links to the wrong place, never arrives because the sender isn’t configured, or uses a code that expires before anyone could type it. Those only show up when a real email reaches a real inbox.
Check it before you merge
- Run the branch. Start it locally, or open the preview deployment if your host creates one for each change.
- Create an address in Proxy Mail QA and sign up, request a magic link or reset a password: whatever the change touched.
- Use the code or link from the row. The code has a Copy button; links become a button named for what they do.
- Read the whole email once. Check the sender, subject, wording and every link in the inbox view.
- Note what you found on the address, so it travels with the test account.
If the link points at localhost on a preview or staging deployment, it’s flagged. That usually means a hard-coded URL or a missing environment variable: see the fixes.
Turn findings into the next task
Give Codex a precise follow-up rather than “email is broken”:
- “On preview deployments the verification link uses
http://localhost:3000. Read the base URL from an environment variable.” - “The code email says 10 minutes but the server rejects codes after 2. Make them match.”
- “Requesting a new magic link should invalidate the previous one.”
Tips
- One address per scenario. Create a small batch, each with a generated name and username, for new user, invited user and reset tests.
- Plus tags for repeated runs.
name+pr482@mailclub.devarrives inname@mailclub.dev, with the tag shown. - Save the password. Keep the password you signed up with on the same row, encrypted and hidden until you need it.