.codex/ is generated by `codex exec` as a machine-local mirror of the .claude hooks.
It is deliberately NOT tracked even though .claude/ is (17 files): its config.toml
embeds a plaintext Gitea credential and absolute /Users paths, so committing it would
leak the credential and would not be portable anyway. Ignoring it also unblocks
scripts/refresh-shared-checkout.sh, which refuses on a dirty tree.
Separately, docs/handoffs/rest-api.md carried the same credential inline; it now
references $ETV_GITEA_BASICAUTH like every other doc. NOTE this does not purge git
history — the literal appears in 12 earlier commits and is still recoverable there.
Refs: #698
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Two-phase handoff for a parallel session: Phase 1 investigates the
existing API/CQRS/validation patterns and produces a design + increment
split (Channels-first); Phase 2 implements per vertical slice via
workflows/ultracode. refs #2
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>