mirror of
https://github.com/openclaw/openclaw.git
synced 2026-08-28 05:16:23 -06:00
codex/buzz-flat-replies
2 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
0dbd5c81d5 |
feat(plugins): one consent screen for plugin capabilities, bound to the reviewed artifact (#130168)
* feat(plugins): surface plugin capability consent in Control UI and CLI Adds plugins.inspect (declared manifest surface, operator grants, install provenance/integrity, ClawHub trust), a Control UI consent dialog on install and external-plugin enable, a server-side acceptance gate persisted on the install record, artifact-anchored widen diffing, and --accept-capabilities for non-interactive CLI use. NOT READY TO LAND: autoreview found critical gaps (see PR notes) — the declared surface omits 20 of 21 contract families, native plugins always report zero hooks, several install/enable paths bypass the gate, and the acknowledgment is not bound to the reviewed surface. * refactor(plugins): bind capability consent to the reviewed surface Collapses the consent error payload to the fields the client cannot fetch (reviewToken, widened, acceptedAt) and pulls identity/declared/grants/source/ trust from plugins.inspect, shrinking the registry-free protocol reader from 395 to 91 lines and removing its divergence from the closed schema. Acknowledgment now carries the SHA-256 reviewToken of the surface the operator saw; the server recomputes the final staged artifact's surface and rejects any mismatch before persisting acceptance. That closes review-then-swap, laundering of forged acceptance through an unchanged update, and cross-artifact replay. All 22 manifest contract families are now declared, hashed and diffed, so a privileged family such as gatewayMethodDispatch can no longer be added without re-consent. Consent reads the manifest runtime discovery will execute, ambiguous install ownership fails closed, integrity resolution has one owner and no longer labels npm SHA-1 shasums as SHA-256, and code plugins disclose that hooks register at runtime instead of rendering an empty "no hooks" row. * fix(gateway): register plugins.inspect in method inventories and regenerate protocol Adds plugins.inspect to the advertised-method inventories (widening the fixed-size slice windows so older indices stay stable), regenerates the Kotlin protocol bindings, drops an unused exported type, and replaces two nested conditional spreads with a plain conditional. * refactor(plugins): split oversized consent modules and clear lint findings Extracts the MCP controller out of the plugins page, unchanged-install reconciliation out of update-installed, and the install lifecycle suite out of the management-service tests, bringing all three back under the max-lines limit without suppressions. Also renames a shadowed binding, drops an unnecessary generic, removes a spread-to-modify in a map, and types catch callbacks as unknown. * chore(protocol): regenerate Kotlin bindings after rebase * feat(plugins): let chat /plugins install review and accept capabilities The consent gate applies to chat installs too, but the command had no way to give consent, so external installs dead-ended on a CLI-only flag. Chat now replies with the plugin's declared capability surface and the exact command to rerun, and accepts a trailing --accept-capabilities mirroring the existing --force acknowledgement. ClawHub trust acknowledgement stays CLI-only. Staged-artifact verification is unchanged: the reviewToken is still checked against the final artifact before acceptance is recorded. * refactor(plugins): single-source the declared-surface groups and manifest precedence The ordered capability group list was defined independently in the consent engine, the protocol error reader, the CLI formatter and the Control UI, so a new contract family had to be added in four places with nothing enforcing it. All four now derive from one canonical list in the protocol schema with a compile-time exhaustiveness guard. Native-versus-bundle manifest precedence is centralized in one helper that both discovery and staged consent call, so the two cannot drift again — that divergence was a real bug where consent read one manifest and the runtime executed another. Also documents that carrying acceptance forward requires pinned artifact integrity, so integrity-less sources such as local paths ask on every install. * fix(plugins): enforce reviewed consent across activation flows Route setup, repair, linked installs, updates, and chat activation through artifact-bound capability consent. Reuse canonical package discovery and recheck staged activation before config publication. Invalidate stale Control UI review requests on reconnect. Verified focused owner and sibling tests, runtime rebuild, and real isolated CLI/Gateway install, inspect, enable, widening, and stale-token rejection flows. * test(plugins): cover beta installs through capability consent * test(plugins): align consent fixtures with staged artifacts * fix(ui): review staged plugin capabilities once * test(ui): inline the remaining plugin consent confirmation * test(plugins): verify consent with deferred install transactions * refactor(setup): share inference execution plan construction * test(ui): settle applied config before deferring refresh * fix(plugins): protect consent provenance and reuse acceptance |
||
|
|
e3c5821d98 |
feat(ui): redesign Channels page with guided channel setup wizard (#106469)
* feat(ui): redesign Channels page with guided channel setup wizard Adds wizard.start flow=channels gateway RPC (additive protocol change) that drives the shared channel-setup wizard (openclaw channels add) over the session step protocol. Control UI Channels page becomes a card hub with plugin-art covers, guided per-channel setup modal (WhatsApp QR pairing via web.login.*, BotFather/Slack/Discord helper links), and a detail overlay hosting the full schema config form. * test(ui): cover channel wizard controller; refresh channels view test props * chore(mock): use non-token-shaped wizard placeholder * test(gateway): scanner-safe auth local in channels wizard test * fix(ui): cancel gateway wizard session on channels page disconnect * fix(ui): adopt browse-all channel pick and guard dirty config before setup * fix(ui): cancel gateway session created by a stale wizard.start * fix(ui): adopt multiselect channel picks; drop redundant String() * fix(ui): track all wizard-adopted channels so WhatsApp QR runs regardless of pick order * feat(gateway): report configured channels on terminal channel-wizard result Replaces the Control UI's channel-adoption heuristic with the authoritative outcome: the channels flow reports its actual selection after config commit, the wizard session surfaces it as an additive channels field on the terminal wizard.next result, and the UI keys WhatsApp QR linking off that. * refactor(ui): align channels hub with the unified settings design language Hub becomes settings-language rows (44px art tiles, status dots, uppercase section headings, hairline groups) instead of a card gallery; the detail overlay hosts the migrated per-channel settings sections with Run setup in the header. Wizard dialog and tile/cover styles move to spacing tokens. * chore(i18n): translate channels hub/setup strings; refresh raw-copy baseline * refactor: satisfy LOC ratchet and dead-export gates Split mock-dev channel/plugin fixtures into their own modules, move wizard runner types/defaults to server-methods/wizard.ts, extract the channels page wizard host and nostr profile HTTP ops, and unexport internal-only types (incl. the unused config-form SECTION_META barrel re-export). * chore(i18n): retranslate channels strings on rebased locale bundles * fix(test): drop redundant String() in channels wizard e2e * fix: address channel-wizard review findings - lock wizard cancellation before durable installs/config writes - report configured channel accounts on the terminal wizard result and start WhatsApp QR pairing for that account (web.login accountId) - forward request options through the browser gateway client so wizard RPC timeouts apply - render skipped setup as a no-change completion - keep detail/advanced config reachable for unconfigured channels - surface the dirty-config warning inside the detail overlay - adopt the picked channel for wizard title/links in browse-all flows * fix(ui): local wizard RPC timeout; translate no-change completion strings |