mirror of
https://github.com/openclaw/openclaw.git
synced 2026-08-22 18:35:21 -06:00
75bcc5cebe
* fix(ui): keep Control UI device identity working on plain-HTTP origins @noble/ed25519 defaults its SHA-512 provider to crypto.subtle, which browsers gate to secure contexts, so device identity silently vanished on http:// LAN dashboards and connects fell back to shared-credential auth with no pairing. Wire a lazy pure-JS @noble/hashes fallback for SHA-512 and the fingerprint SHA-256, and drop the isSecureContext gate in the connect path. Secure contexts keep the platform digests and pay no startup bytes: the fallback loads as its own lazy chunk, kept out of the gateway-runtime startup chunk on purpose. * test(ui): cover device identity minting and signing without crypto.subtle New jsdom regression suite fails on pre-fix code (subtle-less crypto stub with getRandomValues, which real insecure contexts keep). Rewrites the gateway connect tests that previously asserted the device-less insecure fallback: an insecure context now attaches a device identity. * docs(web): plain-HTTP dashboards now pair with a device identity The signing key never crosses the wire, so HTTP+pairing is strictly stronger than the old HTTP token-only fallback; HTTPS (Tailscale Serve) stays the recommendation for transport privacy. * fix(ui): drop unnecessary boolean literal compare in secure-context timing meta * test(ui): declare device.id on the connect-frame test shape * test(ui): split the subtle-less scope-upgrade e2e into the two real invariants Without crypto.subtle the browser can now sign, so the banner offers the explicit admin upgrade; manual-only guidance is reserved for browsers that cannot mint an identity at all (no WebCrypto RNG). Also corrects the connect-path comment: blocked storage yields an ephemeral identity, only a failed mint degrades device-less. * fix(ui): address review findings on the HTTP device-identity path - Storage-blocked pages keep one stable in-memory identity per page lifetime instead of minting a fresh unpaired key on every reconnect, and a write-rejecting store no longer fails the mint (regression tests bite pre-fix). - Connect timing now reports the real browser secure-context fact via a shared browserSecureContext() helper instead of inferring it from device-identity presence. - Docs state the accepted trusted-proxy contract: browsers attach a device identity on every origin, so first connects follow the standard pairing flow (deviceAutoApprove or a one-time approval); device-less admission remains only for browsers that cannot mint an identity. * refactor(ui): trim the connect-path additions under the max-lines cap
58 lines
1.7 KiB
JSON
58 lines
1.7 KiB
JSON
{
|
|
"name": "openclaw-control-ui",
|
|
"private": true,
|
|
"type": "module",
|
|
"scripts": {
|
|
"build": "vite build",
|
|
"dev": "vite",
|
|
"preview": "vite preview",
|
|
"test": "vitest run --config vitest.config.ts"
|
|
},
|
|
"dependencies": {
|
|
"@awesome.me/webawesome": "3.10.0",
|
|
"@codemirror/commands": "6.10.4",
|
|
"@codemirror/language": "6.12.4",
|
|
"@codemirror/language-data": "6.5.2",
|
|
"@codemirror/state": "6.7.1",
|
|
"@codemirror/view": "6.43.6",
|
|
"@lezer/highlight": "1.2.3",
|
|
"@lit/context": "1.1.6",
|
|
"@lit/task": "1.0.3",
|
|
"@modelcontextprotocol/ext-apps": "1.7.5",
|
|
"@modelcontextprotocol/sdk": "1.30.0",
|
|
"@noble/ed25519": "3.1.0",
|
|
"@noble/hashes": "2.2.0",
|
|
"@novnc/novnc": "1.7.0",
|
|
"@openclaw/gateway-client": "workspace:*",
|
|
"@openclaw/gateway-protocol": "workspace:*",
|
|
"@openclaw/libterminal": "0.3.2",
|
|
"@openclaw/media-core": "workspace:*",
|
|
"@openclaw/model-catalog-core": "workspace:*",
|
|
"@openclaw/net-policy": "workspace:*",
|
|
"@openclaw/normalization-core": "workspace:*",
|
|
"@openclaw/session-url-contract": "workspace:*",
|
|
"@openclaw/uirouter": "0.1.1",
|
|
"@openclaw/workboard-contract": "workspace:*",
|
|
"@tanstack/lit-virtual": "3.13.36",
|
|
"@tanstack/virtual-core": "3.17.7",
|
|
"dompurify": "3.4.13",
|
|
"ghostty-web": "0.4.0",
|
|
"highlight.js": "11.11.1",
|
|
"json5": "2.2.3",
|
|
"lit": "3.3.3",
|
|
"markdown-it": "14.3.0",
|
|
"markdown-it-task-lists": "2.1.1",
|
|
"remend": "1.3.0"
|
|
},
|
|
"devDependencies": {
|
|
"@types/markdown-it": "14.1.2",
|
|
"@vitest/browser": "4.1.10",
|
|
"@vitest/browser-playwright": "4.1.10",
|
|
"jsdom": "29.1.1",
|
|
"openclaw": "workspace:*",
|
|
"playwright": "1.62.1",
|
|
"vite": "8.1.5",
|
|
"vitest": "4.1.10"
|
|
}
|
|
}
|