Commit Graph

17550 Commits

Author SHA1 Message Date
zw-xysk ebf9fcc02c fix(feishu): log message content JSON parse failures instead of silently swallowing (#107947)
* fix(feishu): log message content JSON parse failures instead of silently swallowing

Replace formatErrorMessage(err) with safe metadata-only logging in
parseFeishuMessageContent to prevent potential message content leaks
through V8 JSON.parse error messages.

Changes:
- Remove formatErrorMessage import (security: V8 JSON.parse errors can
  include input content in the message)
- Log only msgType and optional messageId (safe metadata) when parse
  fails, never the exception message or raw content
- Add assertion that raw content is NOT present in the log output
- Pass messageId through to enable richer diagnostics

The raw content is still preserved as the function return value (existing
fallback behavior).

* fix(feishu): move parse-failure test into getMessageFeishu suite

The test 'logs a safe diagnostic (not raw content) when message content
is not valid JSON' was declared after the closing brace of
describe('getMessageFeishu'), so it did not inherit that suite's fixture
setup and reset hooks (beforeEach/afterAll). Move it inside the suite
so it benefits from the shared mock reset and cleanup.

Fixes ClawSweeper P2: 'Keep the parse-failure test inside the fetch suite'

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-29 07:16:24 -04:00
wahaha1223 8bcbc3178b fix(msteams): ignore blank certificate settings (#109112)
* fix(msteams): ignore blank certificate settings

* fix(msteams): preserve federated certificate path behavior

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-29 07:10:47 -04:00
Peter Steinberger e6fec4d51b fix(codex): keep completed answers over audit gaps (#115849) 2026-07-29 06:52:21 -04:00
loong 7bdd1f646b fix(memory-host-sdk): resolve stable execPath for worker fork to survive Homebrew Node upgrades (#99318)
* fix(memory): survive Homebrew Node upgrades

Co-authored-by: 袁龙辉0668001277 <yuan.longhui@xydigit.com>

* test(whatsapp): isolate last-route coverage

* fix(deepinfra): preserve offline model compatibility

* test(memory): isolate migration cleanup lifecycle

* test: stabilize aggregate extension gates

* ci: retrigger pull request workflow

* test: preserve inherited Node options

* test(cli): tolerate cold hosted startup

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-29 06:49:02 -04:00
wangmiao0668000666 77e9ee092f fix(synology-chat): stop fabricating send message ids (#110770)
* fix(synology-chat): stop fabricating send message ids

The incoming-webhook send contract acks with a bare boolean and carries
no platform message id, but the adapter returned a synthetic
`sc-${Date.now()}` id and stamped it into the delivery receipt. Return
the established empty-id sentinel and an empty receipt instead, matching
the honest no-platform-id shape used by sibling channels (qqbot,
googlechat) and the plugin-sdk empty-id contract.

Co-Authored-By: Claude <noreply@anthropic.com>

* test(synology-chat): verify truthful webhook receipts

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-29 06:44:44 -04:00
Goutam Adwant b11ed1877c fix(feishu): reply to direct messages by chat id (#109637)
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-29 06:42:41 -04:00
Masato Hoshino 46b2bed375 fix(nextcloud-talk): reject reactions for disabled or unconfigured accounts (#112675)
The react message-action handler dispatched straight to the sender without
checking the resolved account, so a disabled Nextcloud Talk account
(`enabled:false`) that still had a baseUrl/botSecret in config could keep
emitting reactions. `describeMessageTool` already hides the tool for
unconfigured accounts, but an explicit accountId can reach `handleAction`
directly. Enforce the same enabled+configured gate at dispatch, mirroring
the Signal reaction fix (#112607).

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-29 06:34:54 -04:00
Peter Steinberger 986e5d1758 refactor(channels): share ingress retention defaults (#115824) 2026-07-29 06:24:30 -04:00
mushuiyu886 d8935248e4 fix(nostr): profile imports vary on timestamp ties (#111798)
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-29 06:22:33 -04:00
stevenlee-oai a00438a867 fix(codex): restore connected apps for token-authenticated runs (#115075)
* fix(codex): restore connected apps for token-authenticated runs

* fix(codex): keep app inventory protocol types private

* fix(codex): align native runtime with Codex 0.146.0

Co-authored-by: Steven Lee <stevenlee@openai.com>

* fix(codex): clean up latest app-server integration

Co-authored-by: Steven Lee <stevenlee@openai.com>

* fix(codex): keep internal protocol types private

* fix(ci): repair current main Codex landing gates

* fix(ci): format inherited code mode matrix

* fix(codex): reconcile native app-server contracts with main

Prepare a verified GitHub-hosted mainline merge while preserving the reviewed Codex 0.146.0 fixes and canonical OpenAI authentication.

Co-authored-by: Steven Lee <stevenlee@openai.com>

* fix(codex): keep QA evidence in its owning plugin

Resolve the current-main Code Mode test rename without resurrecting the retired core test path.

Co-authored-by: Steven Lee <stevenlee@openai.com>

* fix(codex): enforce canonical OpenAI app-server auth

Reject retired provider aliases without runtime compatibility, direct operators to the doctor migration, and remove the redundant OpenAI API-key predicate.

Co-authored-by: Steven Lee <stevenlee@openai.com>

* chore(codex): reconcile latest main dependency graph

Preserve current main dependency changes while preparing the original Codex PR for an ancestry-preserving signed mainline merge.

Co-authored-by: Steven Lee <stevenlee@openai.com>

* fix(codex): unify bundled Codex 0.146 runtimes

Keep the ACP adapter on the same 0.146.0 Codex release as the managed runtime, remove obsolete 0.145.0 platform artifacts and unused semver compatibility, and preserve the latest main dependency upgrades.

Co-authored-by: Steven Lee <stevenlee@openai.com>

---------

Co-authored-by: Peter Steinberger <peter@steipete.me>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-29 06:21:25 -04:00
Peter Steinberger 7bc453f508 fix(codex): classify hosted search timeouts (#115837) 2026-07-29 06:21:11 -04:00
dongdong 1219ebff9a fix(msteams): keep attachment replies in channel threads (#94348)
* fix(msteams): keep file replies in channel threads

* fix(msteams): keep SharePoint files in channel threads

Fixes #88836 by forwarding channel thread roots through the existing Microsoft Teams proactive activity boundary while preserving top-level, group chat, and personal delivery.

Co-authored-by: Jasmine Zhang <jasminezhang@JasminedeMac-mini.local>

* test(msteams): use lint-safe real SDK HTTP capture

---------

Co-authored-by: Jasmine Zhang <jasminezhang@JasminedeMac-mini.local>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-29 06:19:11 -04:00
Zakaria Rahali a9391d7312 fix(telegram): linkPreview:false is ignored on streamed replies (#114125)
* fix(telegram): linkPreview:false is ignored on streamed replies

Replies delivered through draft streaming still unfurled the first URL
even with channels.telegram.linkPreview: false. Non-streamed sends
already honored the flag.

createTelegramDraftStream never received linkPreview and never set
link_preview_options, on either its initial sendMessage or its
editMessageText calls. Finalization could not clean it up: it skips the
final edit when the streamed draft text already equals the final text,
which is the common case, so the draft message stays as-is with the
preview attached.

Passes linkPreview from telegramCfg into the draft stream and applies
link_preview_options: { is_disabled: true } on the send and on every
edit, since an edit that omits the field re-enables the preview
server-side. Rich messages keep expressing this as skip_entity_detection
at render time, which already worked.

Call arity is preserved when no preview options apply, so existing edit
assertions are unaffected.

Closes #111525

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test(telegram): cover streamed reply option parity

Co-authored-by: Zakaria Rahali <zakariarahali288@gmail.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-29 06:18:35 -04:00
VectorPeak 404fafff77 fix(searxng): avoid duplicating search endpoint (#113661)
Co-authored-by: chatgpt-codex-connector[bot] <199175422+chatgpt-codex-connector[bot]@users.noreply.github.com>
2026-07-29 06:15:51 -04:00
Peter Steinberger 9721ca15d2 refactor(meetings): consolidate runtime facades (#115819)
* refactor(meetings): consolidate runtime facades

* fix(meetings): keep facade contracts acyclic
2026-07-29 06:13:37 -04:00
sunlit-deng da8a2208d2 fix(browser): reject malformed proxy file base64 (#115045)
* fix(browser): reject malformed proxy file base64

* fix(browser): preserve empty proxy downloads

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-29 06:08:01 -04:00
Peter Steinberger 20668eed03 fix(memory): quarantine writes from tainted agent turns (#115818)
* feat(memory): taint writes after network tools

* fix(memory): keep provenance mutations recoverable

* fix(memory): roll back failed provenance writes

* fix(memory): serialize provenance mutations

* docs(memory): explain flush provenance boundary

* refactor(memory): share provenance mutation wrapper

* docs(memory): clarify flush provenance fallback

* fix(memory): canonicalize provenance paths
2026-07-29 06:02:06 -04:00
Chris Zhang 70251e415d fix(feishu): cache inaccessible sender lookups (#111700)
Co-authored-by: Chris <4436110+zqchris@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-29 05:59:55 -04:00
Wynne668 522c747d3c fix(exa): reject invalid UTF-8 search responses (#111736) 2026-07-29 05:58:02 -04:00
Vincent Koc 99b5df0fd2 fix(openai): satisfy realtime lifecycle lint 2026-07-29 17:57:59 +08:00
Vincent Koc 5e0a75f0e5 fix(openai): close realtime lifecycle races 2026-07-29 17:57:59 +08:00
Vincent Koc 1cc2e28b5b chore(openai): keep lifecycle types internal 2026-07-29 17:57:59 +08:00
Vincent Koc 3bf40870ad refactor(openai): apply lifecycle to realtime bridge 2026-07-29 17:57:59 +08:00
Vincent Koc dd0e416303 refactor(openai): apply lifecycle to GPT-Live bridge 2026-07-29 17:57:59 +08:00
Vincent Koc 61cadc1459 refactor(openai): add realtime voice lifecycle 2026-07-29 17:57:59 +08:00
Peter Steinberger cedeca1708 fix(zalo): normalize prefixed Bot API delivery targets (#115814)
Preserve the original Zalo provider and target-kind normalization fix and regression test from #106171. Add real configured-plugin loopback HTTP proof for both text and photo delivery through group and user aliases.

Source: https://github.com/openclaw/openclaw/pull/106171

Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: lzw112 <wang.lizhang@xydigit.com>
2026-07-29 05:53:07 -04:00
Peter Steinberger b0376d19bf fix(browser): abort cancelled CDP handshakes (#115805)
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-29 05:48:27 -04:00
Peter Steinberger 85d2d698ff fix(nostr): deliver oversized encrypted replies as ordered chunks (#115816)
Apply the shared, surrogate-safe outbound chunker to the existing Nostr text limit so the real delivery planner produces ordered NIP-04 events. Preserve assistant-visible sanitization and prove short, word, newline, hard-split, and odd-prefix Unicode boundaries.

Co-authored-by: liyuanbin <li.yuanbin1@xydigit.com>
2026-07-29 05:47:01 -04:00
Vincent Koc 25c375e47f refactor: reuse canonical record guards (#115810)
* docs(agents): standardize canonical record guards

* refactor(model-catalog): use canonical record guard

* refactor(scripts): use canonical record guard

* refactor(ui): use canonical record guard

* refactor(codex): use canonical record guard

* refactor(agents): use canonical record guard

* refactor(sessions): use canonical record guard

* refactor(doctor): use canonical record guard

* refactor(infra): use canonical record guard
2026-07-29 11:43:36 +02:00
joshavant d4b12cb208 fix(qa): prepare shared Slack live flows 2026-07-29 04:38:24 -05:00
Vincent Koc 47c1921d5d fix(ui): stabilize memory engine selection (#115750) 2026-07-29 11:37:39 +02:00
Peter Steinberger bde6b166c0 refactor(channels): deduplicate ingress monitor shells (#115792)
* refactor(channels): deduplicate ingress monitor shells

* fix(channels): preserve ingress error overload types

* fix(channels): type ingress error overload implementation

* chore(plugin-sdk): ratchet ingress error surface
2026-07-29 05:33:00 -04:00
Dallin Romney 92d9da9432 fix(qa): use SQLite Matrix E2EE state (#115748) 2026-07-29 17:32:04 +08:00
Hannes Rudolph 6dc55fa65e fix(plugins): recover user turns with scoped reply hooks (#114836)
Allow before_agent_reply plugins to declare host-enforced trigger eligibility so scheduled-only hooks do not block interrupted user-turn recovery. Keep omitted and malformed scopes fail-closed, scope both memory-core maintenance hooks, and cover three runner reload cycles through the public registration contract.

Refs: #111442

Source: #114836

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-07-29 17:22:16 +08:00
Peter Steinberger 20764dae6d fix(mattermost): preserve private-channel origin identity (#115726)
Preserve the authoritative inbound group origin for private Mattermost channels without changing public channels, direct messages, thread keys, or the native channel delivery target. Prove both Bot API channel types over real HTTP, gateway discovery, and SQLite-backed outbound persistence.

Credit the original group-origin observation in #95669.

Co-authored-by: hansraj <hansraj136@gmail.com>
2026-07-29 05:18:17 -04:00
Peter Steinberger cb8351604e fix(line): mark durably accepted webhook deliveries (#115796)
Emit the established OpenClaw durable-delivery response marker only after an authenticated, non-empty LINE webhook event has been persisted. Verify the production gateway route with signed real HTTP requests covering verification, delayed admission, invalid signatures, and storage failures.

Co-authored-by: 許元豪 <146086744+edenfunf@users.noreply.github.com>
2026-07-29 05:17:15 -04:00
Peter Steinberger 4232126bba chore: update dependencies across workspace (#115677)
* chore(deps): update dependencies

* fix(deps): restore CI compatibility
2026-07-29 05:16:42 -04:00
Peter Steinberger e8524a5839 feat: add Fish Audio S2.1 and local MLX speech (#115790)
* feat: add Fish Audio speech support

* chore: remove unused speech exports

* chore: keep Fish API constant private

* test: remove stale code mode import

* style: use bracket access for Fish voice ids

* test: restore QA evidence validator import
2026-07-29 05:15:33 -04:00
Peter Steinberger 13563478fb fix(mattermost): preserve safe denied-sender group history (#115773)
* fix(mattermost): record pending history for non-allowlisted group senders

When `groupPolicy` is `"allowlist"`, messages from senders not in
`groupAllowFrom` were silently dropped before reaching
`recordPendingHistoryEntryIfEnabled()`. This meant the bot had no
context of what non-allowlisted users said, breaking use cases like
conversation summarization.

This change introduces a `senderBlockedByGroupAllowlist` flag so that
non-allowlisted messages continue through the history-recording code
path before returning without generating a response.

Changes:
1. Add `senderBlockedByGroupAllowlist` flag before access check
2. `GROUP_POLICY_NOT_ALLOWLISTED` sets flag instead of returning
3. Skip `commandGate` check for blocked senders
4. Call `recordPendingHistory()` then return before response processing

Fixes openclaw/openclaw#57607

* test(mattermost): verify denied history over real transport

Co-authored-by: Jason Wang <jasonwang@barkingdog.ai>

---------

Co-authored-by: Jason Wang <jasonwang@barkingdog.ai>
2026-07-29 05:08:22 -04:00
Dallin Romney 0723c68b57 refactor(qa): remove execution sharding (#115787) 2026-07-29 17:06:57 +08:00
Peter Steinberger 994ca7d259 fix(msteams): honor group and channel conversation allowlists (#115746)
* fix(msteams): honor group conversation allowlists

Fixes #95737. Preserve opaque Teams conversation identities, the documented group fallback, personal-DM isolation, and display-name spoof protection.

Based on the original contributor fix in #95764.

Co-authored-by: 周鹤0668001310 <zhou.he3@xydigit.com>

* test(msteams): isolate conversation allowlist regression proof

Co-authored-by: 周鹤0668001310 <zhou.he3@xydigit.com>

---------

Co-authored-by: 周鹤0668001310 <zhou.he3@xydigit.com>
2026-07-29 05:05:42 -04:00
Peter Steinberger dbba7e5c4b fix(nostr): keep private tool traces out of encrypted messages (#115769)
Sanitize both Nostr delivery paths with the shared assistant-visible text contract. Preserve ordinary replies and suppress internal-only messages before Markdown conversion.

Related: #90684

Co-authored-by: liyuanbin <li.yuanbin1@xydigit.com>
2026-07-29 05:01:27 -04:00
Peter Steinberger fb788b79cf feat(memory): retain recent project scopes per session (#115731)
* feat(memory): retain active project set

* refactor(memory): require prepared active set

* docs(memory): explain active project set
2026-07-29 04:58:14 -04:00
Peter Steinberger 94025985f7 fix(feishu): reject unsupported initial document content (#115697) 2026-07-29 04:53:11 -04:00
Peter Steinberger c402688894 feat(media): probe duration and dimensions for playback metadata (#115728)
* feat(media): probe playback metadata

* fix(media): satisfy CI gates

* fix(media): satisfy lint rules
2026-07-29 04:52:17 -04:00
Vincent Koc 30346f9788 fix(sandbox): scope runtimes by workspace (#115766)
Qualify non-shared sandbox identities by resolved workspace while preserving shared runtime names. Existing non-shared runtimes reset once under the new identity.

Related: #51363

Co-authored-by: Tayoun <39609208+tayoun@users.noreply.github.com>
2026-07-29 16:50:38 +08:00
Peter Steinberger 4a19f399be fix(zalo): stop provider startup after gateway shutdown (#115763)
Reconstruct the verified Zalo lifecycle fix from #109990 on current main and preserve its exact production and regression-test blobs.

Source: https://github.com/openclaw/openclaw/pull/109990

Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: LZY3538 <liu.zhenye@xydigit.com>
2026-07-29 04:45:50 -04:00
Peter Steinberger 382ea7b74e refactor: centralize channel streaming config hints (#115739)
* refactor: centralize channel streaming config hints

* fix: repair code mode static checks

* fix: restore QA evidence validator import
2026-07-29 04:42:23 -04:00
ndholakia 726d348bbd fix(msteams): finalize sent replies after dispatch (#82354)
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-07-29 16:40:52 +08:00
Peter Steinberger c5d0b7dd39 refactor: retire legacy provider and secret paths (#115655)
* refactor: retire legacy provider and secret paths

* fix: remove stale cache retention import

* test: remove retired secret marker fallback
2026-07-29 04:36:20 -04:00