The dashboard/Desktop Codex worker (hermes_cli/web_routers/oauth.py) is a deliberate
copy of the CLI poll loop and still treated one transport exception as terminal:
client.post in _codex_poll_authorization had no except, so a single SSL EOF or
ConnectError propagated to _codex_full_login_worker and flipped the session to
status=error, discarding the approval the user had just completed in the browser.
Reuse auth_codex._is_transient_transport_error with the same bounded cap (6
consecutive blips, reset on any response) in the poll loop, and route the two
one-shot POSTs (device-code request, token exchange) through a 3-attempt
retry with the same 1s/2s backoff. Non-transport errors still raise immediately.
Part of #114610