openclaw/src
Vincent Koc 981d266480
security(gateway): block webchat session mutators (#20800)
* chore(ci): local claude settings gitignore

* Gateway: block webchat session mutators

* Changelog: note webchat session mutator guard

* Changelog: credit report for webchat mutator guard
2026-02-19 01:54:02 -08:00
..
acp
agents refactor(agents): dedupe pi subscribe e2e stream fixtures 2026-02-19 09:50:00 +00:00
auto-reply refactor: unify restart gating and update availability sync 2026-02-19 10:00:41 +01:00
browser test(browser): dedupe explicit auth-mode auto-token checks 2026-02-19 08:32:58 +00:00
canvas-host Canvas: improve A2UI asset resolution and empty state (#20312) 2026-02-18 19:44:55 +00:00
channels refactor(shared): centralize @/# slug normalization 2026-02-18 23:34:15 +00:00
cli refactor: unify restart gating and update availability sync 2026-02-19 10:00:41 +01:00
commands test: collapse duplicate onboard auth assertions 2026-02-19 09:13:16 +00:00
compat
config refactor: unify restart gating and update availability sync 2026-02-19 10:00:41 +01:00
cron test(cron): dedupe delayed-timer job assertions 2026-02-19 08:32:58 +00:00
daemon Fix LaunchAgent missing TMPDIR causing SQLITE_CANTOPEN on macOS (#20512) 2026-02-18 21:42:35 -05:00
discord test(discord): dedupe gateway proxy runtime fixture 2026-02-19 07:33:16 +00:00
docs
gateway security(gateway): block webchat session mutators (#20800) 2026-02-19 01:54:02 -08:00
hooks test(hooks): dedupe gmail runtime path assertions 2026-02-19 08:25:12 +00:00
imessage perf(test): simplify shutdown rejection tick wait 2026-02-18 22:05:40 +00:00
infra test: collapse duplicate unhandled rejection fatal cases 2026-02-19 09:40:30 +00:00
line LINE/Security: harden inbound media temp-file naming (#20792) 2026-02-19 09:37:33 +00:00
link-understanding fix: block ISATAP SSRF bypass via shared host/ip guard 2026-02-19 09:59:47 +01:00
logging
macos refactor: unify restart gating and update availability sync 2026-02-19 10:00:41 +01:00
markdown
media refactor(media): unify safe local file reads 2026-02-19 10:21:20 +01:00
media-understanding test(media): dedupe active-model fallback resolver setup 2026-02-19 07:50:10 +00:00
memory test(memory): dedupe voyage embedding provider test setup 2026-02-19 07:37:06 +00:00
node-host refactor(node-host): extract invoke result helpers 2026-02-18 23:48:32 +00:00
pairing
plugin-sdk fix: block ISATAP SSRF bypass via shared host/ip guard 2026-02-19 09:59:47 +01:00
plugins test: merge duplicate plugin memory-none cases 2026-02-19 08:51:38 +00:00
process perf(test): dedupe telegram thread cases and tighten PTY timer 2026-02-18 22:29:31 +00:00
providers
routing
scripts
security refactor(security): share installed plugin directory scan helper 2026-02-19 00:29:07 +00:00
sessions
shared refactor(shared): reuse outbound text chunking core 2026-02-19 07:01:54 +00:00
signal refactor(signal): reuse shared reaction types 2026-02-18 23:34:15 +00:00
slack refactor(slack): share markdown render options 2026-02-18 18:33:48 +00:00
telegram test: remove duplicate telegram de-linkify case 2026-02-19 08:11:42 +00:00
terminal
test-helpers
test-utils
tts
tui refactor(tui): share select list theme styles 2026-02-18 22:31:45 +00:00
types
utils test(queue): cover collect drain helper states 2026-02-19 07:01:54 +00:00
web style: format fs-safe and web media 2026-02-19 09:25:12 +00:00
whatsapp
wizard
channel-web.ts
docker-setup.test.ts fix(docker): harden docker-setup mount validation 2026-02-19 10:44:46 +01:00
dockerfile.test.ts
entry.ts
extensionAPI.ts
globals.ts
index.ts
logger.test.ts test: merge logger subsystem prefix drop cases 2026-02-19 08:49:52 +00:00
logger.ts
logging.ts
polls.test.ts test: table-drive poll duration clamp cases 2026-02-18 23:27:50 +00:00
polls.ts
runtime.ts
utils.test.ts
utils.ts
version.test.ts
version.ts