| Duration | ~75 min in the lesson + ~25 min homework |
| Prerequisites | Lesson 9.2; the checkpoint required by the course lesson chosen for the practice (lesson-1.6 for lesson 2.1). |
| Checkpoint | none (the Do along ends with the chosen lesson's own commit) |
What you will have
The student has completed one real course lesson with Codex, holds a lesson-by-lesson guide to every place where sections 2–8 rely on a Claude Code feature, and has started docs/codex-notes.md, a log of the differences they meet.
Video
The video for this lesson is not recorded yet.
Prompts used in this lesson
Part 3 — Three lessons that need more than a swap
Also keep the pointer lines at the top of our existing AGENTS.md and put the generated AGENTS.md content below them. After the move, show me the first ten lines of AGENTS.md.
Purpose: before I push, I want a security review of everything that differs from origin/main, committed or not. Review only for security: tables or policies that are open to anonymous requests, secrets that could reach the browser, logs or Git, admin pages or endpoints that skip the auth check, unvalidated input, and anything that lets one visitor read another person's data. Done looks like: a list of findings, each with the file, the risk in plain words, how someone could use it, and a suggested fix. If you find nothing, say what you checked. Do not change any file.
Do along
Do these steps on your own project. Most of the time goes to the course lesson you run in step 6.
- Pause after Part 1. Create
docs/codex-notes.mdwith the three columns from Part 1. - After Part 5, choose the lesson. If you work in order, it is lesson 2.1 (start from
lesson-1.6). Otherwise take the next lesson on your path. - Find the lesson's row in the guide and note what you will do differently.
- If you fetched a checkpoint from the reference repository, open
AGENTS.mdand make sure the pointer lines from lesson 9.1 are at the top. - Start
codexin the project. Check/status: Read Only, the right folder. - Follow the lesson from start to finish. Send its prompts as written. Translate on-screen steps with the tables.
- Run every step of the lesson's "Check your work".
- Write one line in
docs/codex-notes.mdfor each difference: an on-screen step you translated, a file in a different place, a result that did not match. - End with the lesson's own commit. Include
docs/codex-notes.mdin it.
Check your work
- Run the chosen lesson's "Check your work" list. Expected: every step gives the expected result, with work done by Codex.
- Open
docs/codex-notes.md. Expected: at least one line, or the sentence "no differences in lesson X.Y". - Start a new Codex session and ask which instruction files it read. Expected:
AGENTS.mdandCLAUDE.md. - Run
git log --oneline -1. Expected: the lesson's commit message. - Point to the row of the guide for lesson 4.7 and say what replaces
/security-review. Expected:/reviewwith security instructions, then the lesson's audit prompt.
Common problems
- A later prompt names a file that does not exist in your project. → Codex organised the code differently from the recording. → Ask: "The course expects
lib/submit-lead.ts. Where is that code here? Do not change anything." Then either use your path in the prompt or ask Codex to move the code, and note it. - Codex stopped following the project rules after lesson 3.2 or after a checkout. →
AGENTS.mdwas replaced and the pointer lines are gone. → Put them back at the top ofAGENTS.mdand start a new session. - A command fails with "Operation not permitted" or cannot reach the network. → It ran inside the sandbox. → Approve when Codex asks to run it with permission, or run it yourself.
- Codex cannot open your local site in the browser. → The development server is not running. → Start
npm run devin your own terminal and give Codex the address. - The result differs from the video. → Run the lesson's checks; they decide, not the video. If one fails, use the cause-first brief from lesson 1.5.
Homework
About 25 minutes, after the lesson, on your own. Nothing later in the course depends on it. The homework of the course lesson you ran is separate; do it with Codex too.
- Mark your road ahead. Go through the guide and pick out every row for a lesson you have not done yet. In
docs/codex-notes.md, add a section "Lessons ahead" with one line per row: the lesson and what you will do in Codex. Deliverable: that section. Done when: it has a line for each of 3.2, 4.7 and 8.3 that is still ahead of you, in your own words. - Your approval rules. List the approval prompts Codex showed during the lesson you ran, and next to each the reason from Part 4: internet, a local port, or the Git folder. Then write, under "My approval rules" in the same file, which commands you will approve after reading and which you will run yourself. Deliverable: three to five lines. Done when: every prompt you saw falls under one of your rules.
- Sort the differences. Read your lines in
docs/codex-notes.mdand mark each "once" or "will come back". For each that will come back, write the sentence you will add to a prompt next time, such as "read docs/brief.md first". If you met no differences, do this after your next lesson. Deliverable: the marked list. Done when: every line has a mark and every "will come back" line has its sentence.
Commit docs/codex-notes.md and push, without a tag.