惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
T
ThreatConnect
SecWiki News
SecWiki News
F
Future of Privacy Forum
AWS News Blog
AWS News Blog
C
Cisco Blogs
A
Arctic Wolf
Vercel News
Vercel News
The GitHub Blog
The GitHub Blog
Scott Helme
Scott Helme
V
V2EX
博客园 - 叶小钗
阮一峰的网络日志
阮一峰的网络日志
K
Kaspersky official blog
G
Google Developers Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
P
Privacy International News Feed
C
Cyber Attacks, Cyber Crime and Cyber Security
N
News | PayPal Newsroom
Schneier on Security
Schneier on Security
NISL@THU
NISL@THU
Microsoft Azure Blog
Microsoft Azure Blog
量子位
The Hacker News
The Hacker News
Stack Overflow Blog
Stack Overflow Blog
Security Latest
Security Latest
M
Microsoft Research Blog - Microsoft Research
Google Online Security Blog
Google Online Security Blog
博客园_首页
C
CXSECURITY Database RSS Feed - CXSecurity.com
I
InfoQ
Google DeepMind News
Google DeepMind News
Y
Y Combinator Blog
The Cloudflare Blog
Microsoft Security Blog
Microsoft Security Blog
Martin Fowler
Martin Fowler
Cisco Talos Blog
Cisco Talos Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Troy Hunt's Blog
F
Fox-IT International blog
S
Security @ Cisco Blogs
博客园 - 司徒正美
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
C
Comments on: Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
L
LINUX DO - 最新话题
GbyAI
GbyAI
Project Zero
Project Zero
腾讯CDC
T
Tailwind CSS Blog

Recent Commits to openclaw:main

fix: tighten Discord voice wake matching (#86595) refactor(logging): share diagnostic message lifecycle fix(cron): restore suspended lanes to default concurrency · openclaw/openclaw@e844d1d fix(auth): emit one-shot doctor-pointer warning for Keychain-only leg… · openclaw/openclaw@a61d530 fix(codex): recover stale preflight bindings (#86602) · openclaw/openclaw@9b9d897 fix(cron): preserve unsupported payload rows on writes · openclaw/openclaw@c916906 fix(cron): canonicalize preserved row ids · openclaw/openclaw@985bc93 test(cron): pin sequential duration regression · openclaw/openclaw@8351556 docs: update changelog for cron preservation (#86415) · openclaw/openclaw@bdc6b32 build: bump qs to patched release · openclaw/openclaw@9330b76 fix(status): prefer active OAuth for runtime aliases chore(acpx): bump bundled acpx to 0.10.0 · openclaw/openclaw@407cf8e docs: make changelog release-owned · openclaw/openclaw@c0f2d89 fix(google): stop appending preview to flash lite · openclaw/openclaw@915c820 docs: update changelog for bug sweep landings · openclaw/openclaw@cd7994f fix(crabbox): detect timed macos js commands · openclaw/openclaw@44bb0be fix(mantis): release telegram user leases on startup failure · openclaw/openclaw@cf27567 fix(agents): keep cron media completions run-scoped · openclaw/openclaw@f5d2db2 fix(agents): deliver stale cron media completions · openclaw/openclaw@f01b2a8 fix(agents): notify stale cron media failures · openclaw/openclaw@baf469f guide workspace-only scratch paths fix(cron): gate lifecycle diagnostic events behind isDiagnosticsEnabled · openclaw/openclaw@4853222 fix(cron): emit message.queued/processed for isolated-agent turns fix(cron): address review — drop unsupported taskLabel, pair with ses… · openclaw/openclaw@804a31e fix(cron): report rotated session in final diagnostics · openclaw/openclaw@207a5a2 fix: hydrate current turn image attachments · openclaw/openclaw@b5ada80 fix(gateway): ignore inherited launchd env for respawn · openclaw/openclaw@177ebdc fix(test): preserve undici exports in discord proxy tests · openclaw/openclaw@b0c8a4d fix: raise default cron concurrency · openclaw/openclaw@bc12e04 fix(doctor): skip restart prompt when gateway is healthy after recent… · openclaw/openclaw@6e8d2db fix: emit agent.send lifecycle hooks on rotation (#85875) · openclaw/openclaw@8129dba fix(crabbox): bootstrap macos shell js commands · openclaw/openclaw@7cd15d2 fix: preflight malformed openshell exec commands fix: tighten openshell exec preflight · openclaw/openclaw@822ee62 docs: clarify unshipped compat policy · openclaw/openclaw@f87aa0f fix(update): allow package-manager hardlinks in swaps · openclaw/openclaw@8061d66 docs: ban repo-hosted proof artifacts · openclaw/openclaw@17954a4 fix(discord): restore bare numeric channel sends (#86571) · openclaw/openclaw@c5b9872 fix(installer): handle alpine apk runtime floors · openclaw/openclaw@b83dfcb fix(security): audit Claude permission overrides under YOLO (#86557) · openclaw/openclaw@bd65b42 fix: speed up Discord voice wake consults · openclaw/openclaw@5ae91f0 fix(qa): harden restart inflight Windows scenario · openclaw/openclaw@3eb06e3 Recover Codex context overflow prompt errors (#85542) · openclaw/openclaw@5cfa577 docs: update changelog for #70473 · openclaw/openclaw@d967760 fix(agents): derive overflow budgets from provider errors · openclaw/openclaw@d5b0174 fix(plugins): only memoize complete metadata snapshots · openclaw/openclaw@3137622 docs: update changelog for media wake fallback (#85489) · openclaw/openclaw@a11d4e6 fix: fallback after active media wake failure (#85489) · openclaw/openclaw@1b64ccb perf(plugins): reuse derived metadata snapshots · openclaw/openclaw@159e440 docs: require maintainer-editable PR branches · openclaw/openclaw@f271f00 fix: scan OpenClaw sessions in agent transcript finder · openclaw/openclaw@4012ae4 docs: note agent transcript OpenClaw session scan · openclaw/openclaw@dd375f9 docs: require generic local fixes · openclaw/openclaw@fc93af5 fix: broaden leading voice wake fuzzing · openclaw/openclaw@a9c91ca test(agents): preserve provider hook mock exports (#86523) · openclaw/openclaw@657b246 Policy: add agent-scoped policy overlays (#85817) · openclaw/openclaw@fbb6340 fix(kilocode): normalize string stop param to array in stream wrapper… · openclaw/openclaw@abe9923 Doctor: expose shell completion health findings (#85566) · openclaw/openclaw@dc17412 fix(agents): honor effective exec policy for Claude live Bash (#86330) fix(test): stabilize e2e runtime imports fix(test): clean plugin gauntlet temp roots · openclaw/openclaw@633e4b8 perf: cache plugin package realpaths (#86517) · openclaw/openclaw@69d728a fix(qa): settle restart races with live budget · openclaw/openclaw@2cac9e5 fix(crabbox): sync full sparse lease runs · openclaw/openclaw@e97e831 fix(qa): extend config mutation Windows budget fix(qa): extend config cleanup Windows budget · openclaw/openclaw@8a93851 test(crabbox): tolerate Windows shell capture · openclaw/openclaw@50d6611 fix(sessions): stop doctor OOM on large session stores and reclaim st… · openclaw/openclaw@89aea9b fix(ollama): strip inline kimi cloud reasoning leak (#86515) fix(discord): merge media captions into one message (#86487) · openclaw/openclaw@bc10fad fix(utils): clamp fetch timeout timers (#85985) fix(ui): preserve user code block rendering (#85942) fix(memory): prevent silent vector index degradation when embedding p… docs: clarify agent transcript placeholders · openclaw/openclaw@8da8bc4 test(qa): annotate live transport RTT measurements · openclaw/openclaw@bb6f37e fix(qqbot): derive outbound watchdog from configured timeouts (#85267… · openclaw/openclaw@aa702cf fix(test): clean kitchen sink rpc temp state · openclaw/openclaw@6f695c1 fix: quiet missing daily memory reads fix: tighten empty plugin registry reuse · openclaw/openclaw@026cfb6 perf: speed up agent transcript lookup · openclaw/openclaw@e7ad116 fix: guard QMD session stem fallback (#86482) · openclaw/openclaw@2e3b59b Guard OpenAI chat payload turns (#86497) · openclaw/openclaw@489e415 fix(gateway): keep session tool mirrors under pressure · openclaw/openclaw@459e89a docs: route github creation through agent transcript test(tools): add unmocked image custom-provider auth regression (#85733) · openclaw/openclaw@f0bfb3f refactor(plugin-sdk): rename plain text tool-call compat wrapper docs(skills): defer private release locators · openclaw/openclaw@23d38e4 Replace Sharp image backend with Photon (#86437) · openclaw/openclaw@b9f975b fix(agents): release embedded-attempt session lock on every exit path… · openclaw/openclaw@32ddfc2 fix: accept OpenClaw voice wake confusions (#86507) fix(crabbox): bootstrap macos js toolchain chore: add agent transcript skill · openclaw/openclaw@d63e8d4 fix(gateway): dedupe session tool fanout · openclaw/openclaw@89a21db fix: Hook ingress token unlocks password-mode gateway auth (#86453) · openclaw/openclaw@d51f268 fix #86077: keep fallback errors candidate scoped (#86134) · openclaw/openclaw@d6b7fe8 fix(diagnostics): reclaim wedged session lanes with a stale leaked ac… · openclaw/openclaw@6f76d9f fix: derive plugin media trust from metadata (#86410) · openclaw/openclaw@e761eb8 fix(media-understanding): normalize HEIC before image descriptions (#… · openclaw/openclaw@75c7236 fix: accept leading fuzzy Discord voice wake names (#86484) · openclaw/openclaw@8fe4f34 feat: promote provider tool call stream wrapper (#86489)
fix: route Discord gateway metadata through proxy (#86601) · openclaw/openclaw@5b6d409
steipete · 2026-05-26 · via Recent Commits to openclaw:main

@@ -37,6 +37,7 @@ const {

3737

globalFetchMock,

3838

HttpsAgent,

3939

HttpsProxyAgent,

40+

fetchWithSsrFGuardMock,

4041

getLastAgent,

4142

getLastProxyAgent,

4243

resolveDebugProxySettingsMock,

@@ -53,6 +54,18 @@ const {

5354

const captureHttpExchangeSpy = vi.fn();

5455

const captureWsEventSpy = vi.fn();

5556

const resolveDebugProxySettingsMock = vi.fn(() => ({ enabled: false }));

57+

const fetchWithSsrFGuardMock = vi.fn(async (params: { url: string; init?: RequestInit }) => {

58+

const source = (await globalFetchMock(params.url, params.init)) as Response;

59+

const body = await source.text();

60+

return {

61+

response: new Response(body, {

62+

status: source.status,

63+

statusText: source.statusText,

64+

headers: source.headers,

65+

}),

66+

release: vi.fn(),

67+

};

68+

});

56695770

const GatewayIntents = {

5871

Guilds: 1 << 0,

@@ -114,6 +127,7 @@ const {

114127

globalFetchMock,

115128

HttpsAgent,

116129

HttpsProxyAgent,

130+

fetchWithSsrFGuardMock,

117131

getLastAgent: () => HttpsAgent.lastCreated,

118132

getLastProxyAgent: () => HttpsProxyAgent.lastCreated,

119133

captureHttpExchangeSpy,

@@ -166,18 +180,7 @@ vi.mock("openclaw/plugin-sdk/proxy-capture", () => ({

166180

}));

167181168182

vi.mock("openclaw/plugin-sdk/ssrf-runtime", () => ({

169-

fetchWithSsrFGuard: vi.fn(async (params: { url: string; init?: RequestInit }) => {

170-

const source = (await globalFetchMock(params.url, params.init)) as Response;

171-

const body = await source.text();

172-

return {

173-

response: new Response(body, {

174-

status: source.status,

175-

statusText: source.statusText,

176-

headers: source.headers,

177-

}),

178-

release: vi.fn(),

179-

};

180-

}),

183+

fetchWithSsrFGuard: fetchWithSsrFGuardMock,

181184

}));

182185183186

describe("createDiscordGatewayPlugin", () => {

@@ -213,6 +216,16 @@ describe("createDiscordGatewayPlugin", () => {

213216

return firstMockCall(mock, label)[index];

214217

}

215218219+

function firstGuardedFetchCall() {

220+

return firstMockArg(fetchWithSsrFGuardMock, "fetchWithSsrFGuardMock") as {

221+

url: string;

222+

init?: RequestInit & { signal?: unknown };

223+

mode?: string;

224+

dispatcherPolicy?: unknown;

225+

policy?: unknown;

226+

};

227+

}

228+216229

function createProxyTestingOverrides() {

217230

return {

218231

HttpsProxyAgentCtor:

@@ -318,6 +331,7 @@ describe("createDiscordGatewayPlugin", () => {

318331

vi.useRealTimers();

319332

baseRegisterClientSpy.mockClear();

320333

globalFetchMock.mockClear();

334+

fetchWithSsrFGuardMock.mockClear();

321335

httpsAgentSpy.mockClear();

322336

wsProxyAgentSpy.mockClear();

323337

webSocketSpy.mockClear();

@@ -504,9 +518,10 @@ describe("createDiscordGatewayPlugin", () => {

504518

expect(Object.getPrototypeOf(plugin)).not.toBe(GatewayPlugin.prototype);

505519

expect(runtime.error).toHaveBeenCalled();

506520

expect(runtime.log).not.toHaveBeenCalled();

521+

expect(fetchWithSsrFGuardMock).not.toHaveBeenCalled();

507522

});

508523509-

it("keeps gateway metadata lookup on the guarded direct fetch when proxy is configured", async () => {

524+

it("routes gateway metadata lookup through the guarded proxy dispatcher", async () => {

510525

const runtime = createRuntime();

511526

const plugin = createDiscordGatewayPlugin({

512527

discordConfig: { proxy: "http://127.0.0.1:8080" },

@@ -516,15 +531,18 @@ describe("createDiscordGatewayPlugin", () => {

516531517532

await registerGatewayClientWithMetadata({ plugin, fetchMock: globalFetchMock });

518533519-

expect(globalFetchMock).toHaveBeenCalledTimes(1);

520-

const fetchInit = firstMockArg(globalFetchMock, "globalFetchMock", 1) as

521-

| { headers?: Record<string, string>; signal?: unknown }

522-

| undefined;

523-

expect(firstMockArg(globalFetchMock, "globalFetchMock")).toBe(

524-

"https://discord.com/api/v10/gateway/bot",

525-

);

526-

expect(fetchInit?.headers).toEqual({ Authorization: "Bot token-123" });

527-

expect(fetchInit?.signal).toBeInstanceOf(AbortSignal);

534+

expect(fetchWithSsrFGuardMock).toHaveBeenCalledTimes(1);

535+

const guardedFetch = firstGuardedFetchCall();

536+

expect(guardedFetch.url).toBe("https://discord.com/api/v10/gateway/bot");

537+

expect(guardedFetch.mode).toBe("trusted_explicit_proxy");

538+

expect(guardedFetch.dispatcherPolicy).toEqual({

539+

mode: "explicit-proxy",

540+

proxyUrl: "http://127.0.0.1:8080",

541+

allowPrivateProxy: true,

542+

});

543+

expect(guardedFetch.policy).toEqual({ allowedHostnames: ["discord.com"] });

544+

expect(guardedFetch.init?.headers).toEqual({ Authorization: "Bot token-123" });

545+

expect(guardedFetch.init?.signal).toBeInstanceOf(AbortSignal);

528546

expect(baseRegisterClientSpy).toHaveBeenCalledTimes(1);

529547

});

530548