惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Vercel News
Vercel News
B
Blog
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
GbyAI
GbyAI
IT之家
IT之家
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Tailwind CSS Blog
博客园_首页
C
Check Point Blog
博客园 - 【当耐特】
美团技术团队
Last Week in AI
Last Week in AI
A
About on SuperTechFans
雷峰网
雷峰网
MongoDB | Blog
MongoDB | Blog
Microsoft Azure Blog
Microsoft Azure Blog
M
MIT News - Artificial intelligence
Martin Fowler
Martin Fowler
J
Java Code Geeks
B
Blog RSS Feed
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
G
Google Developers Blog
F
Fortinet All Blogs

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
fix(secrets): explicitly pass BWS_SERVER_URL to resolver ...
Pandah97 · 2026-06-17 · via Recent Commits to openclaw:main
Original file line numberDiff line numberDiff line change

@@ -335,6 +335,8 @@ the config fields that accept SecretRefs.

335335

- `BWS_ACCESS_TOKEN` available to the Gateway service.

336336

- `PATH` passed to the resolver, or `BWS_BIN` set to the absolute `bws`

337337

binary path.

338+

- `BWS_SERVER_URL` must be set in the environment when using a self-hosted

339+

Bitwarden instance.

338340
339341

```json5

340342

{

@@ -343,7 +345,7 @@ the config fields that accept SecretRefs.

343345

bws: {

344346

source: "exec",

345347

command: "/usr/local/bin/openclaw-bws-resolver.mjs",

346-

passEnv: ["BWS_ACCESS_TOKEN", "PATH", "BWS_BIN"],

348+

passEnv: ["BWS_ACCESS_TOKEN", "BWS_SERVER_URL", "PATH", "BWS_BIN"],

347349

jsonOnly: true,

348350

},

349351

},

Original file line numberDiff line numberDiff line change

@@ -51,6 +51,7 @@ const main = async () => {

5151

encoding: "utf8",

5252

env: {

5353

BWS_ACCESS_TOKEN: process.env.BWS_ACCESS_TOKEN,

54+

BWS_SERVER_URL: process.env.BWS_SERVER_URL,

5455

PATH: process.env.PATH || "",

5556

},

5657

maxBuffer: 1024 * 1024,

Original file line numberDiff line numberDiff line change

@@ -0,0 +1,59 @@

1+

import { spawnSync } from "node:child_process";

2+

import { chmodSync, mkdtempSync, rmSync, writeFileSync } from "node:fs";

3+

import { tmpdir } from "node:os";

4+

import path from "node:path";

5+

import { afterEach, describe, expect, it } from "vitest";

6+
7+

const tempDirs: string[] = [];

8+

const resolverPath = path.resolve("scripts/secrets/openclaw-bws-resolver.mjs");

9+
10+

function makeTempDir(): string {

11+

const dir = mkdtempSync(path.join(tmpdir(), "openclaw-bws-resolver-"));

12+

tempDirs.push(dir);

13+

return dir;

14+

}

15+
16+

afterEach(() => {

17+

for (const dir of tempDirs.splice(0)) {

18+

rmSync(dir, { force: true, recursive: true });

19+

}

20+

});

21+
22+

describe("openclaw-bws-resolver", () => {

23+

it("forwards the self-hosted server URL without inheriting unrelated variables", () => {

24+

const dir = makeTempDir();

25+

const fakeBwsPath = path.join(dir, "bws");

26+

writeFileSync(

27+

fakeBwsPath,

28+

[

29+

"#!/usr/bin/env node",

30+

'if (process.env.BWS_ACCESS_TOKEN !== "test-token") process.exit(10);',

31+

'if (process.env.BWS_SERVER_URL !== "https://bws.example.test") process.exit(11);',

32+

"if (process.env.UNRELATED_PARENT_VALUE !== undefined) process.exit(12);",

33+

'process.stdout.write(JSON.stringify([{ key: "example", value: "resolved" }]));',

34+

].join("\n"),

35+

{ mode: 0o755 },

36+

);

37+

chmodSync(fakeBwsPath, 0o755);

38+
39+

const result = spawnSync(process.execPath, [resolverPath], {

40+

encoding: "utf8",

41+

env: {

42+

BWS_ACCESS_TOKEN: "test-token",

43+

BWS_BIN: fakeBwsPath,

44+

BWS_SERVER_URL: "https://bws.example.test",

45+

PATH: process.env.PATH ?? "",

46+

UNRELATED_PARENT_VALUE: "do-not-forward",

47+

},

48+

input: JSON.stringify({ protocolVersion: 1, ids: ["example"] }),

49+

});

50+
51+

expect(result.status).toBe(0);

52+

expect(result.stderr).toBe("");

53+

expect(JSON.parse(result.stdout)).toEqual({

54+

protocolVersion: 1,

55+

values: { example: "resolved" },

56+

errors: {},

57+

});

58+

});

59+

});