mirror of
https://github.com/openclaw/openclaw.git
synced 2026-08-24 19:35:28 -06:00
8083d4dd3f
* fix(memory): enforce canonical SecretRef resolution Make Gateway runtime snapshots the exclusive owner of memory SecretRef materialization. Bind embedding credentials and headers to provider-owned destinations, and fence per-agent stale reuse by the provider destination/auth contract. Release note: Memory search resolves secret references through configured provider policy and keeps embedding credentials scoped to their intended destination. * fix(lmstudio): preserve resolved memory headers memory remote headers are already materialized by the Gateway snapshot and now bypass SecretRef re-resolution; provider-owned headers retain canonical resolution; final loopback request proof covers literal preservation and precedence. * fix(memory): bind stale credentials to auth owners Resolve memory adapter credential owners from snapshot manifest metadata, conservatively fail cold when metadata is absent, and prove Gemini/Google destination changes plus zero-egress unresolved refs. * fix(memory): scope compatible embedding credentials Apply destination ownership to the core compatible adapter while preserving destination-owned credentials and intentionally unauthenticated endpoints. Distinguish loopback principals, consolidate duplicate security tests, and verify the final credential boundary through a live isolated Gateway request. * test(memory): align destination auth precedence * fix(memory): bind credentials to query identity Include URL query parameters in embedding destination ownership so provider credentials and headers never cross tenant boundaries. * fix(memory): preserve query-bound embedding destinations