Commit Graph

  • 4807e40cbd Agents: restore auth.json static scrub during pi auth discovery joshavant 2026-02-22 15:25:26 -08:00
  • 8e439e2d81 Secrets migrate: ensure unique backup ids per write joshavant 2026-02-22 14:44:24 -08:00
  • a74067d00b Secrets migrate: share helpers and narrow env scrub scope joshavant 2026-02-21 17:08:25 -08:00
  • f6a854bd37 Secrets: add migrate rollback and skill ref support joshavant 2026-02-21 14:23:44 -08:00
  • 2e53033f22 Gateway: serialize secrets activation across reload paths joshavant 2026-02-22 14:41:26 -08:00
  • fe56700026 Gateway: add manual secrets reload command joshavant 2026-02-21 13:57:49 -08:00
  • 301fe18909 Agents: inject pi auth storage from runtime profiles joshavant 2026-02-21 13:42:03 -08:00
  • 6a251d8d74 Auth profiles: resolve keyRef/tokenRef outside gateway joshavant 2026-02-24 15:01:41 -06:00
  • 5ae367aadd Tests: stub discoverAuthStorage in model catalog mocks joshavant 2026-02-24 12:20:57 -06:00
  • cec404225d Auth labels: handle token refs and share Pi credential conversion joshavant 2026-02-22 14:40:16 -08:00
  • e1301c31e7 Auth profiles: never persist plaintext when refs are present joshavant 2026-02-21 17:08:20 -08:00
  • 4c5a2c3c6d Agents: inject pi auth storage from runtime profiles joshavant 2026-02-21 13:42:03 -08:00
  • 45ec5aaf2b Secrets: keep read-only runtime sync in-memory joshavant 2026-02-24 15:01:36 -06:00
  • 8e33ebe471 Secrets: make runtime activation auth loads read-only joshavant 2026-02-24 13:19:02 -06:00
  • 3dbb6be270 Gateway tests: handle async restart callback path joshavant 2026-02-22 15:53:14 -08:00
  • 1560f02561 Gateway: mark restart callback promise as intentionally detached joshavant 2026-02-22 15:38:06 -08:00
  • eb855f75ce Gateway: emit one-shot operator events for secrets degraded/recovered joshavant 2026-02-22 14:37:20 -08:00
  • e45729a430 Secrets runtime: include sourceConfig in prepared snapshot type joshavant 2026-02-21 17:17:50 -08:00
  • e4915cb107 Secrets: preserve runtime snapshot source refs on write joshavant 2026-02-21 17:08:14 -08:00
  • b1533bc80c Gateway: avoid double secrets activation at startup joshavant 2026-02-21 13:23:29 -08:00
  • b50c4c2c44 Gateway: add eager secrets runtime snapshot activation joshavant 2026-02-21 11:13:25 -08:00
  • 2f3b919b94 Config: remove unused extension path helper joshavant 2026-02-24 12:11:38 -06:00
  • d00ed73026 Config: enforce source-specific SecretRef id validation joshavant 2026-02-22 14:36:07 -08:00
  • c3a4251a60 Config: add secret ref schema and redaction foundations joshavant 2026-02-21 10:55:17 -08:00
  • 6daf40d3f4 Gemini OAuth: resolve npm global shim install layouts (#27585) Vincent Koc 2026-02-26 09:43:05 -05:00
  • 79659b2b14 fix(browser): land PR #11880 decodeURIComponent guardrails Peter Steinberger 2026-02-26 14:37:33 +00:00
  • 62a248eb99 core(protocol): pnpm protocol:check Harold Hunt 2026-02-26 08:46:39 -05:00
  • 22b0f36350 fix: add changelog entry for telegram webhook updates (#25732) (thanks @huntharo) Ayaan Zaidi 2026-02-26 20:01:31 +05:30
  • dbfdf60a42 fix(telegram): Allow ephemeral webhookPort Harold Hunt 2026-02-26 08:40:33 -05:00
  • 296210636d fix(telegram): Log bound port if ephemeral (0) is configured Harold Hunt 2026-02-26 08:29:06 -05:00
  • 840b768d97 Telegram: improve webhook config guidance and startup fallback Harold Hunt 2026-02-25 22:06:08 -05:00
  • 5416cabdf8 fix(browser): land PR #21277 dedupe concurrent relay init Peter Steinberger 2026-02-26 14:30:46 +00:00
  • 65d5a91242 fix(browser): land PR #22571 with safe extension handshake handling Peter Steinberger 2026-02-26 14:26:14 +00:00
  • ce833cd6de fix(browser): land PR #24142 flush relay pending timers on stop Peter Steinberger 2026-02-26 14:20:43 +00:00
  • 42cf32c386 fix(browser): land PR #26015 query-token auth for /json relay routes Peter Steinberger 2026-02-26 14:17:31 +00:00
  • 77a3930b72 fix(gateway): allow cron commands to use gateway.remote.token (#27286) 张哲芳 2026-02-26 22:17:30 +08:00
  • 4c75eca580 fix(browser): land PR #23962 extension relay CORS fix Peter Steinberger 2026-02-26 14:14:30 +00:00
  • 081b1aa1ed refactor(gateway): unify v3 auth payload builders and vectors Peter Steinberger 2026-02-26 15:08:40 +01:00
  • 8315c58675 refactor(auth-profiles): unify coercion and add rejected-entry diagnostics Peter Steinberger 2026-02-26 14:42:00 +01:00
  • 96aad965ab fix: land NO_REPLY announce suppression and auth scope assertions Peter Steinberger 2026-02-26 13:40:30 +00:00
  • eb9a968336 fix(slack): suppress NO_REPLY before Slack API call SidQin-cyber 2026-02-26 20:53:24 +08:00
  • 9c142993b8 fix: preserve operator scopes for shared auth connections Kevin Shenghui 2026-02-26 04:11:19 -08:00
  • 0ab5f4c43b fix: enable store=true for Azure OpenAI Responses API Ubuntu 2026-02-26 12:12:20 +00:00
  • 71e45ceecc fix(sessions): add fix-missing cleanup path for orphaned store entries SidQin-cyber 2026-02-26 20:21:47 +08:00
  • a481ed00f5 fix(config): warn and ignore unknown plugin entry keys SidQin-cyber 2026-02-26 20:21:36 +08:00
  • 1ba525f94d fix(telegram): degrade command sync on BOT_COMMANDS_TOO_MUCH SidQin-cyber 2026-02-26 20:22:10 +08:00
  • 79176cc4e5 fix(typing): force cleanup when dispatch idle is never received SidQin-cyber 2026-02-26 21:04:31 +08:00
  • 4b259ab81b fix(models): normalize trailing @profile parsing across resolver paths Peter Steinberger 2026-02-26 14:31:57 +01:00
  • 00e8e88a7c docs(changelog): note auth-profile alias normalization (#26950) (thanks @byungsker) Peter Steinberger 2026-02-26 14:31:53 +01:00
  • 7e7ca43a79 fix(auth-profiles): accept mode/apiKey aliases to prevent silent credential loss lbo728 2026-02-26 08:27:59 +09:00
  • 85b075d0cc fix: record ios talk voice directive hint removal (#27543) (thanks @ngutman) Nimrod Gutman 2026-02-26 15:18:39 +02:00
  • 185c393459 fix(ios): remove talk voice directive hint Nimrod Gutman 2026-02-26 15:05:33 +02:00
  • 490cb5174d fix(apps): sign gateway device auth with v3 payload Peter Steinberger 2026-02-26 14:16:41 +01:00
  • 473a27470f fix(auto-reply): gate inline directives on resolved auth (#27248) Peter Steinberger 2026-02-26 13:11:18 +00:00
  • 7d8aeaaf06 fix(gateway): pin paired reconnect metadata for node policy Peter Steinberger 2026-02-26 14:10:00 +01:00
  • cf311978ea fix(plugins): fallback bundled channel specs when npm install returns 404 (#12849) Vincent Koc 2026-02-26 08:06:54 -05:00
  • 7b5153f214 refactor: dedupe boundary-path canonical checks Peter Steinberger 2026-02-26 14:04:40 +01:00
  • b402770f63 refactor(reply): split abort cutoff and timeout policy modules Peter Steinberger 2026-02-26 14:00:31 +01:00
  • f53e4e9ffb chore: Fix broken build protocol:check Harold Hunt 2026-02-26 07:37:09 -05:00
  • c397a02c9a fix(queue): harden drain/abort/timeout race handling Peter Steinberger 2026-02-26 13:43:30 +01:00
  • 1aef45bc06 fix: harden boundary-path canonical alias handling Peter Steinberger 2026-02-26 13:43:23 +01:00
  • 4b71de384c fix(core): unify session-key normalization and plugin boundary checks Peter Steinberger 2026-02-26 12:40:57 +00:00
  • e3385a6578 fix(security): harden root file guards and host writes Peter Steinberger 2026-02-26 13:32:02 +01:00
  • 2ca2d5ab1c docs: add changelog note for sandbox alias fix Peter Steinberger 2026-02-26 13:30:00 +01:00
  • 4fd29a35bb fix: block broken-symlink sandbox path escapes Peter Steinberger 2026-02-26 13:19:48 +01:00
  • 8b5ebff67b fix(cron): prevent isolated hook session-key double-prefixing (land #27333, @MaheshBhushan) Peter Steinberger 2026-02-26 12:28:07 +00:00
  • f692288301 feat(cron): add --session-key option to cron add/edit CLI commands Matt Hulme 2026-02-25 22:16:51 -06:00
  • 452a8c9db9 fix: use canonical cron session detection for spawn note Ayaan Zaidi 2026-02-26 17:20:45 +05:30
  • 69590de276 fix: suppress SUBAGENT_SPAWN_ACCEPTED_NOTE for cron isolated sessions Taras Lukavyi 2026-02-26 11:34:25 +01:00
  • 46eba86b45 fix: harden workspace boundary path resolution Peter Steinberger 2026-02-26 13:19:55 +01:00
  • ecb2053fdd chore(pr): guard against dropped changelog refs Peter Steinberger 2026-02-26 13:19:21 +01:00
  • 125dc322f5 refactor(feishu): unify account-aware tool routing and message body Peter Steinberger 2026-02-26 13:19:17 +01:00
  • 5df9aacf68 fix(podman): default run-openclaw-podman bind to loopback (land #27491, thanks @robbyczgw-cla) Peter Steinberger 2026-02-26 12:11:50 +00:00
  • a288f3066f fix(gateway): warn on non-loopback bind at startup (land #25397, thanks @let5sne) Peter Steinberger 2026-02-26 12:11:12 +00:00
  • 327f0526d1 fix(gateway): use loopback for CLI status probe when bind=lan (land #26997, thanks @chikko80) Peter Steinberger 2026-02-26 12:10:02 +00:00
  • da53015ef5 fix(onboard): seed Control UI origins for non-loopback binds (land #26157, thanks @stakeswky) Peter Steinberger 2026-02-26 12:09:36 +00:00
  • a97cec0018 refactor: harden remaining plugin manifest reads Peter Steinberger 2026-02-26 13:12:44 +01:00
  • 892a9c24b0 refactor(security): centralize channel allowlist auth policy Peter Steinberger 2026-02-26 13:06:27 +01:00
  • eac86c2081 refactor: unify boundary hardening for file reads Peter Steinberger 2026-02-26 13:04:33 +01:00
  • cf4853e2b8 fix: avoid duplicate feishu permission-error dispatch replies (#27381) (thanks @byungsker) Peter Steinberger 2026-02-26 13:03:29 +01:00
  • 736ec9690f fix(feishu): merge permission error notice into main dispatch instead of separate agent turn lbo728 2026-02-26 18:26:03 +09:00
  • d671d7a0a2 fix: preserve feishu message_id in agent-visible body (#27253) (thanks @xss925175263) Peter Steinberger 2026-02-26 13:01:46 +01:00
  • 6d52b47076 feishu: send message_id in BodyForAgent (fix #27218) xianshishan 2026-02-26 14:44:39 +08:00
  • db6c513d1e feishu: include message_id in agent message body (fix #27218) 咸士山 0668001391 2026-02-26 14:23:55 +08:00
  • 6632fd1ea9 refactor(security): extract protected-route path policy helpers Peter Steinberger 2026-02-26 13:01:12 +01:00
  • 39b5ffdaa6 fix: route feishu doc tools by agent account context (#27338) (thanks @AaronL725) Peter Steinberger 2026-02-26 13:00:15 +01:00
  • 58c100f66f fix(feishu): remove hook registration, fix docx getClient call root 2026-02-26 08:52:41 +00:00
  • 10d9549764 fix(feishu): fix hook types and docx client call root 2026-02-26 08:44:06 +00:00
  • 151ee6014a fix(feishu): route doc tools by agent account root 2026-02-26 08:27:23 +00:00
  • 8bdda7a651 fix(security): keep DM pairing allowlists out of group auth Peter Steinberger 2026-02-26 12:58:06 +01:00
  • d08dafb08f fix(feishu): bitable tools use listEnabledFeishuAccounts for multi-account mode (#27244) echoVic 2026-02-26 14:30:24 +08:00
  • 0ed675b1df fix(security): harden canonical auth matching for plugin channel routes Peter Steinberger 2026-02-26 12:55:23 +01:00
  • 0231cac957 feat(typing): add TTL safety-net for stuck indicators (land #27428, thanks @Crpdim) Peter Steinberger 2026-02-26 11:48:35 +00:00
  • 3d30ba18a2 fix(slack): gate member and message subtype system events Peter Steinberger 2026-02-26 12:48:10 +01:00
  • da0ba1b73a fix(security): harden channel auth path checks and exec approval routing Peter Steinberger 2026-02-26 12:45:56 +01:00
  • b096ad267e fix(telegram): add sendChatAction 401 backoff guard (land #27415, thanks @widingmarcus-cyber) Peter Steinberger 2026-02-26 11:45:43 +00:00
  • b74be2577f refactor(web): unify proxy-guarded fetch path for web tools Peter Steinberger 2026-02-26 12:44:06 +01:00
  • 8bf1c9a23a fix(typing): stop keepalive restarts after run completion (land #27413, thanks @widingmarcus-cyber) Peter Steinberger 2026-02-26 11:41:38 +00:00
  • fec3fdf7ef test(msteams): align silent-prefix expectation with exact NO_REPLY semantics Peter Steinberger 2026-02-26 11:41:37 +00:00
  • 242188b7b1 refactor: unify boundary-safe reads for bootstrap and includes Peter Steinberger 2026-02-26 12:42:06 +01:00