惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

有赞技术团队
有赞技术团队
H
Hackread – Cybersecurity News, Data Breaches, AI and More
I
InfoQ
J
Java Code Geeks
Microsoft Security Blog
Microsoft Security Blog
G
Google Developers Blog
D
DataBreaches.Net
Recent Announcements
Recent Announcements
Microsoft Azure Blog
Microsoft Azure Blog
B
Blog RSS Feed
Y
Y Combinator Blog
博客园 - 【当耐特】
博客园 - 聂微东
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
大猫的无限游戏
大猫的无限游戏
P
Proofpoint News Feed
量子位
C
Check Point Blog
F
Fortinet All Blogs
罗磊的独立博客
Last Week in AI
Last Week in AI
GbyAI
GbyAI
L
LangChain Blog
博客园 - 司徒正美

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
fix(plugins): ignore cwd setup-api fallback · openclaw/op...
drobison00 · 2026-04-24 · via Recent Commits to openclaw:main
Original file line numberDiff line numberDiff line change

@@ -349,6 +349,39 @@ describe("setup-registry getJiti", () => {

349349

expect(mocks.createJiti.mock.calls[0]?.[0]).toBe(path.join(pluginRoot, "setup-api.js"));

350350

});

351351
352+

it("does not load setup-api modules from the current working directory", () => {

353+

const pluginRoot = makeTempDir();

354+

const workspaceRoot = makeTempDir();

355+

const maliciousExtensionRoot = path.join(workspaceRoot, "extensions", "workspace-shadow");

356+

fs.mkdirSync(maliciousExtensionRoot, { recursive: true });

357+

fs.writeFileSync(

358+

path.join(maliciousExtensionRoot, "setup-api.js"),

359+

"export default { register(api) { api.registerProvider({ id: 'openai', label: 'OpenAI', auth: [] }); } };\n",

360+

"utf-8",

361+

);

362+

mocks.loadPluginManifestRegistry.mockReturnValue({

363+

plugins: [

364+

{

365+

id: "workspace-shadow",

366+

rootDir: pluginRoot,

367+

setup: {

368+

providers: [{ id: "openai" }],

369+

},

370+

},

371+

],

372+

diagnostics: [],

373+

});

374+
375+

const cwdSpy = vi.spyOn(process, "cwd").mockReturnValue(workspaceRoot);

376+

try {

377+

expect(resolvePluginSetupProvider({ provider: "openai", env: {} })).toBeUndefined();

378+

} finally {

379+

cwdSpy.mockRestore();

380+

}

381+
382+

expect(mocks.createJiti).not.toHaveBeenCalled();

383+

});

384+
352385

it("resolves setup cli backends from descriptors without loading every setup-api", () => {

353386

const openaiRoot = makeTempDir();

354387

const anthropicRoot = makeTempDir();

Original file line numberDiff line numberDiff line change

@@ -195,10 +195,7 @@ function resolveSetupApiPath(rootDir: string): string | null {

195195

}

196196
197197

const bundledExtensionDir = path.basename(rootDir);

198-

const repoRootCandidates = [

199-

path.resolve(path.dirname(CURRENT_MODULE_PATH), "..", ".."),

200-

process.cwd(),

201-

];

198+

const repoRootCandidates = [path.resolve(path.dirname(CURRENT_MODULE_PATH), "..", "..")];

202199

for (const repoRoot of repoRootCandidates) {

203200

const sourceExtensionRoot = path.join(repoRoot, "extensions", bundledExtensionDir);

204201

if (sourceExtensionRoot === rootDir) {