惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
Y
Y Combinator Blog
博客园_首页
V
Visual Studio Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
阮一峰的网络日志
阮一峰的网络日志
Hugging Face - Blog
Hugging Face - Blog
宝玉的分享
宝玉的分享
B
Blog
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
WordPress大学
WordPress大学
L
LangChain Blog
爱范儿
爱范儿
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
P
Proofpoint News Feed
Blog — PlanetScale
Blog — PlanetScale
C
Check Point Blog
博客园 - 聂微东
云风的 BLOG
云风的 BLOG
Microsoft Security Blog
Microsoft Security Blog
博客园 - 叶小钗
酷 壳 – CoolShell
酷 壳 – CoolShell
H
Help Net Security

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
fix(qa): sanitize evidence preview roots · openclaw/openc...
vincentkoc · 2026-06-20 · via Recent Commits to openclaw:main

@@ -104,6 +104,16 @@ function displayGalleryPath(

104104

return sanitizeGalleryText(value, params);

105105

}

106106107+

function sanitizeGalleryPreview(

108+

value: string | null,

109+

params: {

110+

extraRoots?: readonly string[];

111+

repoRoot: string;

112+

},

113+

) {

114+

return value === null ? null : sanitizeGalleryText(value, params);

115+

}

116+107117

async function realpathIfExists(filePath: string): Promise<string | null> {

108118

return fs.realpath(filePath).catch(() => null);

109119

}

@@ -356,6 +366,7 @@ function artifactHref(evidencePath: string, artifactPath: string) {

356366

async function buildProducerContextFile(params: {

357367

allowedRoots: readonly string[];

358368

artifactPath: string;

369+

extraRoots: readonly string[];

359370

filePath: string;

360371

hrefEvidencePath: string;

361372

previewKind: "json" | "text";

@@ -369,7 +380,14 @@ async function buildProducerContextFile(params: {

369380

return {

370381

href: artifactHref(params.hrefEvidencePath, params.artifactPath),

371382

path: repoPath,

372-

preview: await readPreview(realFile, params.previewKind).catch(() => null),

383+

preview: await readPreview(realFile, params.previewKind)

384+

.then((preview) =>

385+

sanitizeGalleryPreview(preview, {

386+

extraRoots: params.extraRoots,

387+

repoRoot: params.repoRoot,

388+

}),

389+

)

390+

.catch(() => null),

373391

};

374392

}

375393

@@ -422,9 +440,19 @@ async function buildArtifactView(params: {

422440

kind: params.artifact.kind,

423441

mediaKind,

424442

path: displayPath,

425-

preview: await readPreview(realFile, mediaKind).catch(

426-

(error: unknown) => `Preview unavailable: ${formatErrorMessage(error)}`,

427-

),

443+

preview: await readPreview(realFile, mediaKind)

444+

.then((preview) =>

445+

sanitizeGalleryPreview(preview, {

446+

extraRoots: params.extraRoots,

447+

repoRoot: params.repoRoot,

448+

}),

449+

)

450+

.catch((error: unknown) =>

451+

sanitizeGalleryText(`Preview unavailable: ${formatErrorMessage(error)}`, {

452+

extraRoots: params.extraRoots,

453+

repoRoot: params.repoRoot,

454+

}),

455+

),

428456

source: params.artifact.source,

429457

};

430458

}

@@ -603,6 +631,7 @@ async function findUxMatrixProducerRoot(params: {

603631604632

async function buildProducerContext(params: {

605633

evidencePath: string;

634+

extraRoots: readonly string[];

606635

hrefEvidencePath: string;

607636

repoRoot: string;

608637

summaryEntries: readonly QaEvidenceSummaryEntry[];

@@ -632,6 +661,7 @@ async function buildProducerContext(params: {

632661

await buildProducerContextFile({

633662

allowedRoots,

634663

artifactPath: toRepoRelativePath(repoRoot, producerPaths[file.key]),

664+

extraRoots: params.extraRoots,

635665

filePath: producerPaths[file.key],

636666

hrefEvidencePath: params.hrefEvidencePath,

637667

previewKind: file.previewKind,

@@ -784,6 +814,7 @@ export async function buildQaEvidenceGalleryModel(params: {

784814

profile: summary.profile ?? null,

785815

producerContext: await buildProducerContext({

786816

evidencePath,

817+

extraRoots: [requestedRepoRoot],

787818

hrefEvidencePath,

788819

repoRoot,

789820

summaryEntries: summary.entries,