惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
SegmentFault 最新的问题
J
Java Code Geeks
V
V2EX
Blog — PlanetScale
Blog — PlanetScale
博客园 - 司徒正美
Hugging Face - Blog
Hugging Face - Blog
F
Fortinet All Blogs
aimingoo的专栏
aimingoo的专栏
B
Blog
A
About on SuperTechFans
有赞技术团队
有赞技术团队
月光博客
月光博客
Microsoft Azure Blog
Microsoft Azure Blog
阮一峰的网络日志
阮一峰的网络日志
腾讯CDC
美团技术团队
大猫的无限游戏
大猫的无限游戏
爱范儿
爱范儿
N
Netflix TechBlog - Medium
C
Check Point Blog
Recent Announcements
Recent Announcements
博客园 - Franky
博客园 - 叶小钗
T
Tailwind CSS Blog

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
fix(device-pair): reject invalid remote setup URLs · open...
clawsweeper · 2026-04-30 · via Recent Commits to openclaw:main

@@ -70,6 +70,7 @@ type ApprovedPairingDevice = ApprovedPairingResult["device"];

7070

const INTERNAL_PAIRING_SCOPES = ["operator.write", "operator.pairing"];

71717272

function createApi(params?: {

73+

config?: OpenClawPluginApi["config"];

7374

runtime?: OpenClawPluginApi["runtime"];

7475

pluginConfig?: Record<string, unknown>;

7576

registerCommand?: (command: OpenClawPluginCommandDefinition) => void;

@@ -78,7 +79,7 @@ function createApi(params?: {

7879

id: "device-pair",

7980

name: "device-pair",

8081

source: "test",

81-

config: {

82+

config: params?.config ?? {

8283

gateway: {

8384

auth: {

8485

mode: "token",

@@ -96,6 +97,7 @@ function createApi(params?: {

9697

}

97989899

function registerPairCommand(params?: {

100+

config?: OpenClawPluginApi["config"];

99101

runtime?: OpenClawPluginApi["runtime"];

100102

pluginConfig?: Record<string, unknown>;

101103

}): OpenClawPluginCommandDefinition {

@@ -649,6 +651,36 @@ describe("device-pair /pair default setup code", () => {

649651

expect(result).toEqual({ text: "Error: Configured publicUrl is invalid." });

650652

});

651653654+

it("rejects invalid gateway.remote.url before falling back to bind-derived setup urls", async () => {

655+

const command = registerPairCommand({

656+

config: {

657+

gateway: {

658+

bind: "custom",

659+

customBindHost: "127.0.0.1",

660+

remote: { url: "http://localhost:notaport" },

661+

auth: {

662+

mode: "token",

663+

token: "gateway-token",

664+

},

665+

},

666+

},

667+

pluginConfig: {

668+

publicUrl: undefined,

669+

},

670+

});

671+

const result = await command.handler(

672+

createCommandContext({

673+

channel: "webchat",

674+

args: "",

675+

commandBody: "/pair",

676+

gatewayClientScopes: ["operator.write", "operator.pairing"],

677+

}),

678+

);

679+680+

expect(pluginApiMocks.issueDeviceBootstrapToken).not.toHaveBeenCalled();

681+

expect(result).toEqual({ text: "Error: Configured gateway.remote.url is invalid." });

682+

});

683+652684

it.each([

653685

"http://localhost:notaport",

654686

"http:gateway.example.test",