惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
Google DeepMind News
Google DeepMind News
博客园 - 【当耐特】
量子位
博客园 - 司徒正美
爱范儿
爱范儿
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
Jina AI
Jina AI
J
Java Code Geeks
腾讯CDC
大猫的无限游戏
大猫的无限游戏
V
Visual Studio Blog
I
InfoQ
D
Docker
Recent Announcements
Recent Announcements
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
宝玉的分享
宝玉的分享
G
Google Developers Blog
GbyAI
GbyAI
Y
Y Combinator Blog
有赞技术团队
有赞技术团队
H
Help Net Security

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
fix(mattermost): bound successful REST JSON/text response...
Alix-007 · 2026-06-28 · via Recent Commits to openclaw:main
11

// Mattermost plugin module implements client behavior.

22

import { resolveTimerTimeoutMs } from "openclaw/plugin-sdk/number-runtime";

3-

import { readResponseTextLimited } from "openclaw/plugin-sdk/provider-http";

3+

import {

4+

readProviderJsonResponse,

5+

readResponseTextLimited,

6+

} from "openclaw/plugin-sdk/provider-http";

7+

import { readResponseWithLimit } from "openclaw/plugin-sdk/response-limit-runtime";

48

import { sleep } from "openclaw/plugin-sdk/runtime-env";

59

import {

610

fetchWithSsrFGuard,

@@ -13,6 +17,13 @@ import {

1317

import { z } from "zod";

14181519

const MATTERMOST_ERROR_BODY_LIMIT_BYTES = 8 * 1024;

20+

// Mattermost REST control-plane JSON (posts, users, channels, file-upload

21+

// results) stays well under a megabyte; cap successful JSON the same way the

22+

// shared provider path is capped so an untrusted/self-hosted homeserver cannot

23+

// stream an unbounded body into the runtime before parsing.

24+

// Non-JSON success bodies are a rare fallback (the API is JSON-first); keep a

25+

// generous text budget but still bound it instead of buffering the whole stream.

26+

const MATTERMOST_TEXT_RESPONSE_LIMIT_BYTES = 64 * 1024;

1627

const NULL_BODY_STATUSES = new Set([101, 204, 205, 304]);

17281829

export type MattermostFetch = (input: RequestInfo | URL, init?: RequestInit) => Promise<Response>;

@@ -84,6 +95,14 @@ function buildMattermostApiUrl(baseUrl: string, path: string): string {

8495

return `${normalized}/api/v4${suffix}`;

8596

}

869798+

async function readMattermostSuccessText(res: Response, path: string): Promise<string> {

99+

const bytes = await readResponseWithLimit(res, MATTERMOST_TEXT_RESPONSE_LIMIT_BYTES, {

100+

onOverflow: ({ maxBytes }) =>

101+

new Error(`Mattermost API ${path}: text response exceeds ${maxBytes} bytes`),

102+

});

103+

return new TextDecoder().decode(bytes);

104+

}

105+87106

export async function readMattermostError(res: Response): Promise<string> {

88107

const contentType = res.headers.get("content-type") ?? "";

89108

if (!res.body) {

@@ -214,9 +233,9 @@ export function createMattermostClient(params: {

214233215234

const contentType = res.headers.get("content-type") ?? "";

216235

if (contentType.includes("application/json")) {

217-

return (await res.json()) as T;

236+

return await readProviderJsonResponse<T>(res, `Mattermost API ${path}`);

218237

}

219-

return (await res.text()) as T;

238+

return (await readMattermostSuccessText(res, path)) as T;

220239

};

221240222241

return { baseUrl, apiBaseUrl, token, request, fetchImpl };

@@ -679,7 +698,10 @@ export async function uploadMattermostFile(

679698

const detail = await readMattermostError(res);

680699

throw new Error(`Mattermost API ${res.status} ${res.statusText}: ${detail || "unknown error"}`);

681700

}

682-

const data = (await res.json()) as { file_infos?: MattermostFileInfo[] };

701+

const data = await readProviderJsonResponse<{ file_infos?: MattermostFileInfo[] }>(

702+

res,

703+

"Mattermost API /files",

704+

);

683705

const info = data.file_infos?.[0];

684706

if (!info?.id) {

685707

throw new Error("Mattermost file upload failed");