Files
openclaw/extensions/imessage/src/approval-auth.ts
T
Peter Steinberger 83bf0379c9 refactor(channels): share plugin contract scaffolds (#105838)
* refactor(channels): share plugin contract scaffolds

* fix: preserve channel config hint metadata

* chore: refresh Plugin SDK API baseline

* ci: refresh plugin SDK surface budget

* fix(ci): allow read-only state database boundary

* fix(ci): dedupe read-only state database boundary
2026-07-13 01:51:32 -07:00

46 lines
1.8 KiB
TypeScript

// Imessage plugin module implements approval auth behavior.
import { createChannelApprovalAuth } from "openclaw/plugin-sdk/approval-auth-runtime";
import { resolveIMessageAccount } from "./accounts.js";
import { normalizeIMessageHandle } from "./targets.js";
function normalizeIMessageApproverId(value: string | number): string | undefined {
const raw = String(value).trim();
if (!raw) {
return undefined;
}
// Normalize first so service-prefixed direct handles (`imessage:+...`,
// `sms:+...`, `auto:+...`) are stripped to their bare identifier before we
// decide whether to reject the entry. After normalization only the
// conversation-target prefixes (chat_id / chat_guid / chat_identifier) remain
// as illegal approver shapes — service-prefixed direct handles are valid
// approver values that map to a specific phone/email.
const normalized = normalizeIMessageHandle(raw);
if (
!normalized ||
normalized.startsWith("chat_id:") ||
normalized.startsWith("chat_guid:") ||
normalized.startsWith("chat_identifier:")
) {
return undefined;
}
return normalized;
}
function normalizeIMessageApproverEntry(value: string | number): string | undefined {
return String(value).trim() === "*" ? "*" : normalizeIMessageApproverId(value);
}
const imessageApproval = createChannelApprovalAuth({
channelLabel: "iMessage",
resolveInputs: ({ cfg, accountId }) => {
const account = resolveIMessageAccount({ cfg, accountId });
return { allowFrom: account.config.allowFrom };
},
normalizeApprover: normalizeIMessageApproverEntry,
normalizeSenderId: normalizeIMessageApproverId,
isWildcardAuthorized: ({ purpose, approvers }) => purpose === "action" && approvers.includes("*"),
});
export const getIMessageApprovalApprovers = imessageApproval.resolveApprovers;
export const imessageApprovalAuth = imessageApproval.approvalAuth;