openclaw/src
Peter Steinberger e3e0ffd801 feat(security): audit gateway HTTP no-auth exposure 2026-02-19 14:25:56 +01:00
..
acp style: align formatting with oxfmt 0.33 2026-02-18 01:34:35 +00:00
agents refactor(exec): split host flows and harden safe-bin trust 2026-02-19 14:22:01 +01:00
auto-reply fix: enforce inbound attachment root policy across pipelines 2026-02-19 14:15:51 +01:00
browser refactor(browser): unify navigation guard path and error typing 2026-02-19 14:04:18 +01:00
canvas-host Canvas: improve A2UI asset resolution and empty state (#20312) 2026-02-18 19:44:55 +00:00
channels refactor(shared): centralize @/# slug normalization 2026-02-18 23:34:15 +00:00
cli refactor: unify restart gating and update availability sync 2026-02-19 10:00:41 +01:00
commands fix(doctor): skip embedding provider check when QMD backend is active (openclaw#17295) thanks @miloudbelarebia 2026-02-19 07:21:27 -06:00
compat
config fix: enforce inbound attachment root policy across pipelines 2026-02-19 14:15:51 +01:00
cron Security: use crypto.randomBytes for temp file names (#20654) 2026-02-19 03:19:29 -08:00
daemon Security: use execFileSync instead of execSync with shell strings (#20655) 2026-02-19 03:19:09 -08:00
discord fix(security): escape backticks in exec-approval command previews (#20854) 2026-02-19 03:17:06 -08:00
docs
gateway security: add baseline security headers to gateway HTTP responses (#10526) 2026-02-19 03:28:24 -08:00
hooks test(hooks): dedupe gmail runtime path assertions 2026-02-19 08:25:12 +00:00
imessage fix: enforce inbound attachment root policy across pipelines 2026-02-19 14:15:51 +01:00
infra refactor(exec): split host flows and harden safe-bin trust 2026-02-19 14:22:01 +01:00
line refactor(security): share safe temp media path builder (#20810) 2026-02-19 09:59:21 +00:00
link-understanding fix: block ISATAP SSRF bypass via shared host/ip guard 2026-02-19 09:59:47 +01:00
logging style: align formatting with oxfmt 0.33 2026-02-18 01:34:35 +00:00
macos refactor: unify restart gating and update availability sync 2026-02-19 10:00:41 +01:00
markdown fix(security): use YAML core schema to prevent type coercion (#20857) 2026-02-19 03:15:36 -08:00
media fix: enforce inbound attachment root policy across pipelines 2026-02-19 14:15:51 +01:00
media-understanding fix: enforce inbound attachment root policy across pipelines 2026-02-19 14:15:51 +01:00
memory test(memory): dedupe voyage embedding provider test setup 2026-02-19 07:37:06 +00:00
node-host refactor(exec): split host flows and harden safe-bin trust 2026-02-19 14:22:01 +01:00
pairing style: align formatting with oxfmt 0.33 2026-02-18 01:34:35 +00:00
plugin-sdk refactor(security): harden temp-path handling for inbound media 2026-02-19 14:06:37 +01:00
plugins Security: add explicit opt-in for deprecated plugin runtime exec (#20874) 2026-02-19 11:30:36 +00:00
process perf(test): dedupe telegram thread cases and tighten PTY timer 2026-02-18 22:29:31 +00:00
providers style: align formatting with oxfmt 0.33 2026-02-18 01:34:35 +00:00
routing refactor(test): dedupe agent harnesses and routing fixtures 2026-02-18 04:49:22 +00:00
scripts
security feat(security): audit gateway HTTP no-auth exposure 2026-02-19 14:25:56 +01:00
sessions style: align formatting with oxfmt 0.33 2026-02-18 01:34:35 +00:00
shared refactor(shared): reuse outbound text chunking core 2026-02-19 07:01:54 +00:00
signal refactor(signal): reuse shared reaction types 2026-02-18 23:34:15 +00:00
slack refactor(slack): share markdown render options 2026-02-18 18:33:48 +00:00
telegram test: remove duplicate telegram de-linkify case 2026-02-19 08:11:42 +00:00
terminal refactor(cli): share styled select prompt helper 2026-02-18 17:48:02 +00:00
test-helpers
test-utils refactor: dedupe provider usage fetch logic and tests 2026-02-19 12:51:30 +00:00
tts Security: use crypto.randomBytes for temp file names (#20654) 2026-02-19 03:19:29 -08:00
tui fix(security): block plaintext WebSocket connections to non-loopback addresses (#20803) 2026-02-19 03:13:08 -08:00
types
utils test(queue): cover collect drain helper states 2026-02-19 07:01:54 +00:00
web style: format fs-safe and web media 2026-02-19 09:25:12 +00:00
whatsapp test: dedupe line and whatsapp target resolution tests 2026-02-18 05:31:13 +00:00
wizard style: align formatting with oxfmt 0.33 2026-02-18 01:34:35 +00:00
channel-web.ts
docker-setup.test.ts fix(docker): harden docker-setup mount validation 2026-02-19 10:44:46 +01:00
dockerfile.test.ts test(docker): cover browser install build arg 2026-02-16 22:35:27 -05:00
entry.ts
extensionAPI.ts
globals.ts
index.ts
logger.test.ts test: merge logger subsystem prefix drop cases 2026-02-19 08:49:52 +00:00
logger.ts
logging.ts style: align formatting with oxfmt 0.33 2026-02-18 01:34:35 +00:00
polls.test.ts test: table-drive poll duration clamp cases 2026-02-18 23:27:50 +00:00
polls.ts
runtime.ts chore: chore: Fix types in tests 12/N. 2026-02-17 11:22:49 +09:00
utils.test.ts
utils.ts
version.test.ts refactor: centralize presence routing and version precedence coverage (#19609) 2026-02-18 00:02:51 -05:00
version.ts refactor: centralize presence routing and version precedence coverage (#19609) 2026-02-18 00:02:51 -05:00