openclaw/docs
Glucksberg 34e2425b4d
fix(security): restrict MEDIA path extraction to prevent LFI (#4930)
* fix(security): restrict inbound media staging to media directory

* docs: update MEDIA path guidance for security restrictions

- Update agent hint to warn against absolute/~ paths
- Update docs example to use https:// instead of /tmp/

---------

Co-authored-by: Evan Otero <evanotero@google.com>
2026-01-31 10:55:37 -08:00
..
_layouts refactor: rename to openclaw 2026-01-30 03:16:21 +01:00
assets Add files via upload 2026-01-29 23:37:32 -05:00
automation docs: format cron jobs doc 2026-01-31 22:46:19 +05:30
channels fix: restore telegram draft streaming partials 2026-01-31 22:46:19 +05:30
cli chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
concepts Agents: add system prompt safety guardrails (#5445) 2026-01-31 15:50:15 +01:00
debug chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
diagnostics chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
experiments chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
gateway Agents: add system prompt safety guardrails (#5445) 2026-01-31 15:50:15 +01:00
help chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
hooks refactor: rename to openclaw 2026-01-30 03:16:21 +01:00
images docs: add group flow diagram 2026-01-10 20:05:22 +01:00
install chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
nodes chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
platforms chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
plugins chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
providers chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
refactor chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
reference chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
security chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
start fix(security): restrict MEDIA path extraction to prevent LFI (#4930) 2026-01-31 10:55:37 -08:00
tools chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
web chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
CNAME refactor: rename to openclaw 2026-01-30 03:16:21 +01:00
_config.yml refactor: rename to openclaw 2026-01-30 03:16:21 +01:00
bedrock.md chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
brave-search.md chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
broadcast-groups.md chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
date-time.md chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
debugging.md chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
docs.json chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
environment.md chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
hooks.md chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
index.md Docs: fix index logo dark mode (#5474) 2026-01-31 15:55:59 +01:00
logging.md chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
multi-agent-sandbox-tools.md chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
network.md chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
northflank.mdx chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
perplexity.md chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
pi-dev.md docs: add pi and pi-dev documentation 2026-01-31 04:20:12 +01:00
pi.md Agents: add system prompt safety guardrails (#5445) 2026-01-31 15:50:15 +01:00
plugin.md chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
prose.md chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
railway.mdx chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
render.mdx chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
scripts.md chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
testing.md chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
token-use.md chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
tts.md chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
tui.md chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
vps.md chore: Run `pnpm format:fix`. 2026-01-31 21:13:13 +09:00
whatsapp-openclaw.jpg refactor: rename to openclaw 2026-01-30 03:16:21 +01:00