慣性聚合 高效追蹤和閱讀你感興趣的部落格、新聞、科技資訊
閱讀原文 在慣性聚合中打開

推薦訂閱源

小众软件
小众软件
博客园 - 叶小钗
有赞技术团队
有赞技术团队
大猫的无限游戏
大猫的无限游戏
博客园_首页
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
L
LangChain Blog
Hugging Face - Blog
Hugging Face - Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
aimingoo的专栏
aimingoo的专栏
Blog — PlanetScale
Blog — PlanetScale
爱范儿
爱范儿
T
Tailwind CSS Blog
Jina AI
Jina AI
量子位
Stack Overflow Blog
Stack Overflow Blog
人人都是产品经理
人人都是产品经理
J
Java Code Geeks
V
Visual Studio Blog
月光博客
月光博客

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4 test: trim doctor command hotspots · openclaw/openclaw@c66f16a test: isolate agent auth and spawn hotspots · openclaw/openclaw@9285935 test: stabilize MCP startup disposal race · openclaw/openclaw@dd9d2eb test: merge browser contract server suites · openclaw/openclaw@5817a76 test: narrow ollama provider discovery setup · openclaw/openclaw@a0d9598 build: declare qa-lab aimock runtime dependency · openclaw/openclaw@24431e5 test: speed up safe-bins exec harness · openclaw/openclaw@ee856ab test: preserve tool helpers in embedded runner mocks · openclaw/openclaw@acd86a0 refactor: move memory embeddings into provider plugins · openclaw/openclaw@77e6e4c test: reuse system-run temp fixtures · openclaw/openclaw@7e9ff0f test: trim hotspot wait overhead · openclaw/openclaw@12a59b0 Check: avoid duplicate boundary prep · openclaw/openclaw@baf11b8 test: reduce hotspot fixture overhead · openclaw/openclaw@3a59edd feat(ui): overhaul settings and slash command UX (#67819) thanks @Bun… · openclaw/openclaw@2cfb660 QA Matrix: exit cleanly on failure · openclaw/openclaw@42805d2 QA Matrix: isolate scenario coverage · openclaw/openclaw@7e659e1 Matrix: refresh crypto bootstrap state · openclaw/openclaw@94081d8 QA Lab: add provider registry · openclaw/openclaw@bb7e982 Matrix: add plugin changelog · openclaw/openclaw@4acab55 test: trim more hotspot overhead · openclaw/openclaw@f485311
修復(閘道):綁定網路聊天圖片數據掃描 · openclaw/openclaw@bde1bad
vincentkoc · 2026-05-28 · via Recent Commits to openclaw:main

@@ -2,6 +2,7 @@ import path from "node:path";

22

import type { ReplyPayload } from "../../auto-reply/reply-payload.js";

33

import { openLocalFileSafely } from "../../infra/fs-safe.js";

44

import { assertNoWindowsNetworkPath, safeFileURLToPath } from "../../infra/local-file-access.js";

5+

import { estimateBase64DecodedBytes } from "../../media/base64.js";

56

import { assertLocalMediaAllowed, LocalMediaAccessError } from "../../media/local-media-access.js";

67

import { isAudioFileName } from "../../media/mime.js";

78

import { resolveSendableOutboundReplyParts } from "../../plugin-sdk/reply-payload.js";

@@ -131,10 +132,31 @@ function mimeTypeForPath(filePath: string): string {

131132

return MIME_BY_EXT[ext] ?? "audio/mpeg";

132133

}

133134134-

function estimateBase64DecodedBytes(base64: string): number {

135-

const sanitized = base64.replace(/\s+/g, "");

136-

const padding = sanitized.endsWith("==") ? 2 : sanitized.endsWith("=") ? 1 : 0;

137-

return Math.floor((sanitized.length * 3) / 4) - padding;

135+

function isBase64DataPayload(value: string): boolean {

136+

if (value.length === 0) {

137+

return false;

138+

}

139+

for (let index = 0; index < value.length; index += 1) {

140+

const code = value.charCodeAt(index);

141+

const isBase64Char =

142+

(code >= 0x41 && code <= 0x5a) ||

143+

(code >= 0x61 && code <= 0x7a) ||

144+

(code >= 0x30 && code <= 0x39) ||

145+

code === 0x2b ||

146+

code === 0x2f ||

147+

code === 0x3d;

148+

const isWhitespace =

149+

code === 0x09 ||

150+

code === 0x0a ||

151+

code === 0x0b ||

152+

code === 0x0c ||

153+

code === 0x0d ||

154+

code === 0x20;

155+

if (!isBase64Char && !isWhitespace) {

156+

return false;

157+

}

158+

}

159+

return true;

138160

}

139161140162

function resolveEmbeddableImageUrl(url: string): string | null {

@@ -145,12 +167,17 @@ function resolveEmbeddableImageUrl(url: string): string | null {

145167

if (trimmed.length > MAX_WEBCHAT_IMAGE_DATA_URL_CHARS) {

146168

return null;

147169

}

148-

const match = /^data:(image\/[a-z0-9.+-]+);base64,([a-z0-9+/=\s]+)$/i.exec(trimmed);

149-

if (!match) {

170+

const commaIndex = trimmed.indexOf(",");

171+

if (commaIndex < 0) {

172+

return null;

173+

}

174+

const metadata = trimmed.slice(0, commaIndex);

175+

const match = /^data:(image\/[a-z0-9.+-]+);base64$/i.exec(metadata);

176+

const base64Data = trimmed.slice(commaIndex + 1);

177+

if (!match || !isBase64DataPayload(base64Data)) {

150178

return null;

151179

}

152180

const mediaType = normalizeLowercaseStringOrEmpty(match[1]);

153-

const base64Data = match[2];

154181

if (!ALLOWED_WEBCHAT_DATA_IMAGE_MEDIA_TYPES.has(mediaType)) {

155182

return null;

156183

}