惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hugging Face - Blog
Hugging Face - Blog
Vercel News
Vercel News
C
Check Point Blog
G
Google Developers Blog
博客园 - 司徒正美
量子位
Engineering at Meta
Engineering at Meta
S
SegmentFault 最新的问题
Google DeepMind News
Google DeepMind News
F
Fortinet All Blogs
A
About on SuperTechFans
美团技术团队
D
DataBreaches.Net
Stack Overflow Blog
Stack Overflow Blog
Jina AI
Jina AI
Y
Y Combinator Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Apple Machine Learning Research
Apple Machine Learning Research
J
Java Code Geeks
MongoDB | Blog
MongoDB | Blog
人人都是产品经理
人人都是产品经理
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The Cloudflare Blog
U
Unit 42

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
docs: document gateway client auth helpers · openclaw/ope...
steipete · 2026-06-05 · via Recent Commits to openclaw:main
Original file line numberDiff line numberDiff line change

@@ -1,3 +1,5 @@

1+

// Gateway RPC call helper.

2+

// Builds a GatewayClient, resolves auth/scopes, and performs one request.

13

import { randomUUID } from "node:crypto";

24

import { isLoopbackIpAddress } from "@openclaw/net-policy/ip";

35

import { redactSensitiveUrlLikeString } from "@openclaw/net-policy/redact-sensitive-url";

Original file line numberDiff line numberDiff line change

@@ -1,3 +1,5 @@

1+

// Gateway client bootstrap resolver.

2+

// Collects URL, auth, and handshake settings before constructing a GatewayClient.

13

import type { OpenClawConfig } from "../config/types.openclaw.js";

24

import { resolveGatewayConnectionAuth } from "./connection-auth.js";

35

import { buildGatewayConnectionDetailsWithResolvers } from "./connection-details.js";

Original file line numberDiff line numberDiff line change

@@ -1,3 +1,5 @@

1+

// OpenClaw Gateway client facade.

2+

// Wraps the shared gateway-client package with OpenClaw host dependencies.

13

import {

24

GatewayClient as BaseGatewayClient,

35

GATEWAY_CLOSE_CODE_HINTS as BASE_GATEWAY_CLOSE_CODE_HINTS,

@@ -191,6 +193,8 @@ export class GatewayClient {

191193

#client: BaseGatewayClient;

192194
193195

constructor(opts: GatewayClientOptions) {

196+

// Inject host deps here so the reusable package stays decoupled from

197+

// OpenClaw device identity, token storage, proxy routing, and logging.

194198

this.#client = new BaseGatewayClient({

195199

...opts,

196200

clientVersion: opts.clientVersion ?? VERSION,

Original file line numberDiff line numberDiff line change

@@ -1,3 +1,5 @@

1+

// Gateway connection auth facade.

2+

// Resolves config-backed client credentials with or without async SecretRefs.

13

import type { OpenClawConfig } from "../config/types.openclaw.js";

24

import { resolveGatewayCredentialsWithSecretInputs } from "./credentials-secret-inputs.js";

35

import { resolveGatewayCredentialsFromConfig } from "./credentials.js";

Original file line numberDiff line numberDiff line change

@@ -1,3 +1,5 @@

1+

// Gateway HTTP auth helpers.

2+

// Authenticates HTTP endpoints and derives trusted operator scopes.

13

import type { IncomingMessage, ServerResponse } from "node:http";

24

import {

35

normalizeLowercaseStringOrEmpty,

@@ -27,6 +29,8 @@ export function getHeader(req: IncomingMessage, name: string): string | undefine

2729

}

2830
2931

export function getBearerToken(req: IncomingMessage): string | undefined {

32+

// Bearer parsing is intentionally minimal: callers pass the extracted token

33+

// into the shared gateway auth verifier for constant-time comparison.

3034

const raw = normalizeOptionalString(getHeader(req, "authorization")) ?? "";

3135

if (!normalizeLowercaseStringOrEmpty(raw).startsWith("bearer ")) {

3236

return undefined;

Original file line numberDiff line numberDiff line change

@@ -1,3 +1,5 @@

1+

// Gateway probe auth resolver.

2+

// Adapts gateway credential precedence for local/remote reachability checks.

13

import { normalizeOptionalString } from "@openclaw/normalization-core/string-coerce";

24

import type { OpenClawConfig } from "../config/types.openclaw.js";

35

import { resolveGatewayCredentialsWithSecretInputs } from "./credentials-secret-inputs.js";

Original file line numberDiff line numberDiff line change

@@ -1,3 +1,5 @@

1+

// Gateway probe target resolver.

2+

// Chooses local or remote probe mode from gateway config and URL availability.

13

import { normalizeOptionalString } from "@openclaw/normalization-core/string-coerce";

24

import type { OpenClawConfig } from "../config/types.openclaw.js";

35
Original file line numberDiff line numberDiff line change

@@ -1,3 +1,5 @@

1+

// Gateway reachability probe client.

2+

// Connects to a gateway and summarizes auth, health, status, and presence.

13

import { randomUUID } from "node:crypto";

24

import path from "node:path";

35

import {

@@ -105,6 +107,8 @@ function hasProbeAuth(auth: GatewayProbeAuth | undefined): boolean {

105107

}

106108
107109

function shouldShortCircuitDeviceRequiredProbe(cacheKey: string, nowMs: number): boolean {

110+

// Repeated unauthenticated probes can trigger pairing/device-required closes.

111+

// Short-circuit briefly so status checks do not spam the gateway.

108112

const entry = deviceRequiredProbeCache.get(cacheKey);

109113

if (!entry) {

110114

return false;

Original file line numberDiff line numberDiff line change

@@ -1,3 +1,5 @@

1+

// Gateway startup Control UI origin seeding.

2+

// Adds runtime-only browser origins for non-loopback binds when safe.

13

import {

24

ensureControlUiAllowedOriginsForNonLoopbackBind,

35

type GatewayNonLoopbackBindMode,

@@ -23,6 +25,8 @@ export async function maybeSeedControlUiAllowedOriginsAtStartup(params: {

2325

if (!seeded.seededOrigins || !seeded.bind) {

2426

return { config: params.config, seededAllowedOrigins: false };

2527

}

28+

// This changes only the runtime config object. Operators still need explicit

29+

// config entries for additional browser origins.

2630

params.log.info(buildSeededOriginsInfoLog(seeded.seededOrigins, seeded.bind));

2731

return { config: seeded.config, seededAllowedOrigins: true };

2832

}