惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
WordPress大学
WordPress大学
月光博客
月光博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
大猫的无限游戏
大猫的无限游戏
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - 聂微东
Apple Machine Learning Research
Apple Machine Learning Research
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
雷峰网
雷峰网
小众软件
小众软件
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 叶小钗
美团技术团队
宝玉的分享
宝玉的分享
Hugging Face - Blog
Hugging Face - Blog
阮一峰的网络日志
阮一峰的网络日志
A
About on SuperTechFans
Jina AI
Jina AI
D
Docker
Last Week in AI
Last Week in AI
MongoDB | Blog
MongoDB | Blog
Stack Overflow Blog
Stack Overflow Blog
Microsoft Azure Blog
Microsoft Azure Blog

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
fix(cli): request admin scope for admin device approvals ...
steipete · 2026-05-03 · via Recent Commits to openclaw:main

@@ -0,0 +1,110 @@

1+

---

2+

summary: "Operator roles, scopes, and approval-time checks for Gateway clients"

3+

read_when:

4+

- Debugging missing operator scope errors

5+

- Reviewing device or node pairing approvals

6+

- Adding or classifying Gateway RPC methods

7+

title: "Operator scopes"

8+

---

9+10+

Operator scopes define what a Gateway client may do after it authenticates.

11+

They are a control-plane guardrail inside one trusted Gateway operator domain,

12+

not hostile multi-tenant isolation. If you need strong separation between

13+

people, teams, or machines, run separate Gateways under separate OS users or

14+

hosts.

15+16+

Related: [Security](/gateway/security), [Gateway protocol](/gateway/protocol),

17+

[Gateway pairing](/gateway/pairing), [Devices CLI](/cli/devices).

18+19+

## Roles

20+21+

Gateway WebSocket clients connect with one role:

22+23+

- `operator`: control-plane clients such as CLI, Control UI, automation, and

24+

trusted helper processes.

25+

- `node`: capability hosts such as macOS, iOS, Android, or headless nodes that

26+

expose commands through `node.invoke`.

27+28+

Operator RPC methods require the `operator` role. Node-originated methods

29+

require the `node` role.

30+31+

## Scope levels

32+33+

| Scope | Meaning |

34+

| ----------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |

35+

| `operator.read` | Read-only status, lists, catalog, logs, session reads, and other non-mutating control-plane calls. |

36+

| `operator.write` | Normal mutating operator actions such as sending messages, invoking tools, updating talk/voice settings, and node command relay. Also satisfies `operator.read`. |

37+

| `operator.admin` | Administrative control-plane access. Satisfies every `operator.*` scope. Required for config mutation, updates, native hooks, sensitive reserved namespaces, and high-risk approvals. |

38+

| `operator.pairing` | Device and node pairing management, including listing, approving, rejecting, removing, rotating, and revoking pairing records or device tokens. |

39+

| `operator.approvals` | Exec and plugin approval APIs. |

40+

| `operator.talk.secrets` | Reading Talk configuration with secrets included. |

41+42+

Unknown future `operator.*` scopes require an exact match unless the caller has

43+

`operator.admin`.

44+45+

## Method scope is only the first gate

46+47+

Each Gateway RPC has a least-privilege method scope. That method scope decides

48+

whether the request can reach the handler. Some handlers then apply stricter

49+

approval-time checks based on the concrete thing being approved or mutated.

50+51+

Examples:

52+53+

- `device.pair.approve` is reachable with `operator.pairing`, but approving an

54+

operator device can only mint or preserve scopes the caller already holds.

55+

- `node.pair.approve` is reachable with `operator.pairing`, then derives extra

56+

approval scopes from the pending node command list.

57+

- `chat.send` is normally a write-scoped method, but persistent `/config set`

58+

and `/config unset` require `operator.admin` at command level.

59+60+

This lets lower-scope operators perform low-risk pairing actions without making

61+

all pairing approval admin-only.

62+63+

## Device pairing approvals

64+65+

Device pairing records are the durable source of approved roles and scopes.

66+

Already paired devices do not get broader access silently: reconnects that ask

67+

for a broader role or broader scopes create a new pending upgrade request.

68+69+

When approving a device request:

70+71+

- A request with no operator role does not need operator token scope approval.

72+

- A request for `operator.read`, `operator.write`, `operator.approvals`,

73+

`operator.pairing`, or `operator.talk.secrets` requires the caller to hold

74+

those scopes, or `operator.admin`.

75+

- A request for `operator.admin` requires `operator.admin`.

76+

- A repair request with no explicit scopes can inherit the existing operator

77+

token scopes. If that existing token is admin-scoped, approval still requires

78+

`operator.admin`.

79+80+

For paired-device token sessions, management is self-scoped unless the caller

81+

also has `operator.admin`: non-admin callers can rotate, revoke, or remove only

82+

their own device entry.

83+84+

## Node pairing approvals

85+86+

Legacy `node.pair.*` uses a separate Gateway-owned node pairing store. WS nodes

87+

use device pairing with `role: node`, but the same approval-level vocabulary

88+

applies.

89+90+

`node.pair.approve` uses the pending request command list to derive additional

91+

required scopes:

92+93+

- Commandless request: `operator.pairing`

94+

- Non-exec node commands: `operator.pairing` + `operator.write`

95+

- `system.run`, `system.run.prepare`, or `system.which`:

96+

`operator.pairing` + `operator.admin`

97+98+

Node pairing establishes identity and trust. It does not replace the node's

99+

own `system.run` exec approval policy.

100+101+

## Shared-secret auth

102+103+

Shared gateway token/password auth is treated as trusted operator access for

104+

that Gateway. OpenAI-compatible HTTP surfaces and `/tools/invoke` restore the

105+

normal full operator default scope set for shared-secret bearer auth, even if a

106+

caller sends narrower declared scopes.

107+108+

Identity-bearing modes, such as trusted proxy auth or private-ingress `none`,

109+

can still honor explicit declared scopes. Use separate Gateways for real trust

110+

boundary separation.