惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
云风的 BLOG
云风的 BLOG
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
D
Docker
H
Help Net Security
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Tailwind CSS Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
月光博客
月光博客
C
Check Point Blog
S
SegmentFault 最新的问题
T
The Blog of Author Tim Ferriss
J
Java Code Geeks
M
MIT News - Artificial intelligence
B
Blog RSS Feed
MyScale Blog
MyScale Blog
大猫的无限游戏
大猫的无限游戏
Hugging Face - Blog
Hugging Face - Blog
腾讯CDC
美团技术团队
I
InfoQ
Blog — PlanetScale
Blog — PlanetScale

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
fix: tighten webhook exposure host checks (#75465) · open...
clawsweeper · 2026-05-01 · via Recent Commits to openclaw:main

@@ -59,9 +59,13 @@ const fetchGuardMocks = vi.hoisted(() => ({

5959

),

6060

}));

616162-

vi.mock("openclaw/plugin-sdk/ssrf-runtime", () => ({

63-

fetchWithSsrFGuard: fetchGuardMocks.fetchWithSsrFGuard,

64-

}));

62+

vi.mock("openclaw/plugin-sdk/ssrf-runtime", async (importOriginal) => {

63+

const actual = await importOriginal<typeof import("openclaw/plugin-sdk/ssrf-runtime")>();

64+

return {

65+

...actual,

66+

fetchWithSsrFGuard: fetchGuardMocks.fetchWithSsrFGuard,

67+

};

68+

});

65696670

vi.mock("./src/voice-call-gateway.js", () => ({

6771

joinMeetViaVoiceCallGateway: voiceCallMocks.joinMeetViaVoiceCallGateway,

@@ -1481,48 +1485,55 @@ describe("google-meet plugin", () => {

14811485

);

14821486

});

148314871484-

it("reports local voice-call publicUrl as unusable for Twilio transport", async () => {

1485-

vi.stubEnv("TWILIO_ACCOUNT_SID", "AC123");

1486-

vi.stubEnv("TWILIO_AUTH_TOKEN", "secret");

1487-

vi.stubEnv("TWILIO_FROM_NUMBER", "+15550001234");

1488-

const { tools } = setup(

1489-

{ defaultTransport: "twilio" },

1490-

{

1491-

fullConfig: {

1492-

plugins: {

1493-

allow: ["google-meet", "voice-call"],

1494-

entries: {

1495-

"voice-call": {

1496-

enabled: true,

1497-

config: {

1498-

provider: "twilio",

1499-

publicUrl: "http://127.0.0.1:3334/voice/webhook",

1488+

it.each([

1489+

"http://127.0.0.1:3334/voice/webhook",

1490+

"http://[::1]:3334/voice/webhook",

1491+

"http://[fd00::1]/voice/webhook",

1492+

])(

1493+

"reports local voice-call publicUrl %s as unusable for Twilio transport",

1494+

async (publicUrl) => {

1495+

vi.stubEnv("TWILIO_ACCOUNT_SID", "AC123");

1496+

vi.stubEnv("TWILIO_AUTH_TOKEN", "secret");

1497+

vi.stubEnv("TWILIO_FROM_NUMBER", "+15550001234");

1498+

const { tools } = setup(

1499+

{ defaultTransport: "twilio" },

1500+

{

1501+

fullConfig: {

1502+

plugins: {

1503+

allow: ["google-meet", "voice-call"],

1504+

entries: {

1505+

"voice-call": {

1506+

enabled: true,

1507+

config: {

1508+

provider: "twilio",

1509+

publicUrl,

1510+

},

15001511

},

15011512

},

15021513

},

15031514

},

15041515

},

1505-

},

1506-

);

1507-

const tool = tools[0] as {

1508-

execute: (

1509-

id: string,

1510-

params: unknown,

1511-

) => Promise<{ details: { ok?: boolean; checks?: unknown[] } }>;

1512-

};

1516+

);

1517+

const tool = tools[0] as {

1518+

execute: (

1519+

id: string,

1520+

params: unknown,

1521+

) => Promise<{ details: { ok?: boolean; checks?: unknown[] } }>;

1522+

};

151315231514-

const result = await tool.execute("id", { action: "setup_status" });

1524+

const result = await tool.execute("id", { action: "setup_status" });

151515251516-

expect(result.details.ok).toBe(false);

1517-

expect(result.details.checks).toEqual(

1518-

expect.arrayContaining([

1519-

expect.objectContaining({

1520-

id: "twilio-voice-call-webhook",

1521-

ok: false,

1522-

}),

1523-

]),

1524-

);

1525-

});

1526+

expect(result.details.ok).toBe(false);

1527+

expect(result.details.checks).toEqual(

1528+

expect.arrayContaining([

1529+

expect.objectContaining({

1530+

id: "twilio-voice-call-webhook",

1531+

ok: false,

1532+

}),

1533+

]),

1534+

);

1535+

},

1536+

);

1526153715271538

it("opens local Chrome Meet in observe-only mode without BlackHole checks", async () => {

15281539

const originalPlatform = process.platform;