惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
J
Java Code Geeks
Blog — PlanetScale
Blog — PlanetScale
F
Fortinet All Blogs
腾讯CDC
大猫的无限游戏
大猫的无限游戏
Jina AI
Jina AI
WordPress大学
WordPress大学
雷峰网
雷峰网
小众软件
小众软件
D
DataBreaches.Net
V
Visual Studio Blog
博客园 - Franky
IT之家
IT之家
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
B
Blog RSS Feed
博客园 - 聂微东
T
Tailwind CSS Blog
有赞技术团队
有赞技术团队
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Security Blog
Microsoft Security Blog
G
Google Developers Blog
云风的 BLOG
云风的 BLOG

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
telegram: align model picker callback auth (#70235) · ope...
drobison00 · 2026-04-23 · via Recent Commits to openclaw:main

@@ -6,14 +6,18 @@ import {

66

resolveInboundDebounceMs,

77

} from "openclaw/plugin-sdk/channel-inbound";

88

import { resolveStoredModelOverride } from "openclaw/plugin-sdk/command-auth";

9+

import {

10+

resolveCommandAuthorization,

11+

resolveCommandAuthorizedFromAuthorizers,

12+

} from "openclaw/plugin-sdk/command-auth-native";

913

import { buildCommandsMessagePaginated } from "openclaw/plugin-sdk/command-status";

1014

import { writeConfigFile } from "openclaw/plugin-sdk/config-runtime";

1115

import {

1216

loadSessionStore,

1317

resolveSessionStoreEntry,

1418

updateSessionStore,

1519

} from "openclaw/plugin-sdk/config-runtime";

16-

import type { DmPolicy } from "openclaw/plugin-sdk/config-runtime";

20+

import type { DmPolicy, OpenClawConfig } from "openclaw/plugin-sdk/config-runtime";

1721

import type { TelegramGroupConfig, TelegramTopicConfig } from "openclaw/plugin-sdk/config-runtime";

1822

import { applyModelOverrideToSessionEntry } from "openclaw/plugin-sdk/config-runtime";

1923

import {

@@ -60,6 +64,7 @@ import {

6064

import { resolveMedia } from "./bot/delivery.js";

6165

import {

6266

getTelegramTextParts,

67+

buildTelegramGroupFrom,

6368

buildTelegramGroupPeerId,

6469

buildTelegramParentPeer,

6570

resolveTelegramForumFlag,

@@ -783,6 +788,76 @@ export const registerTelegramHandlers = ({

783788

return { allowed: true };

784789

};

785790791+

const isTelegramModelCallbackAuthorized = (params: {

792+

chatId: number;

793+

isGroup: boolean;

794+

senderId: string;

795+

senderUsername: string;

796+

context: TelegramEventAuthorizationContext;

797+

cfg: OpenClawConfig;

798+

}): boolean => {

799+

const { chatId, isGroup, senderId, senderUsername, context, cfg } = params;

800+

const useAccessGroups = cfg.commands?.useAccessGroups !== false;

801+

const dmAllowFrom = context.groupAllowOverride ?? allowFrom;

802+

const commandsAllowFrom = cfg.commands?.allowFrom;

803+

const commandsAllowFromConfigured =

804+

commandsAllowFrom != null &&

805+

typeof commandsAllowFrom === "object" &&

806+

(Array.isArray(commandsAllowFrom.telegram) || Array.isArray(commandsAllowFrom["*"]));

807+

if (commandsAllowFromConfigured) {

808+

return resolveCommandAuthorization({

809+

ctx: {

810+

Provider: "telegram",

811+

Surface: "telegram",

812+

OriginatingChannel: "telegram",

813+

AccountId: accountId,

814+

ChatType: isGroup ? "group" : "direct",

815+

From: isGroup

816+

? buildTelegramGroupFrom(chatId, context.resolvedThreadId)

817+

: `telegram:${chatId}`,

818+

SenderId: senderId || undefined,

819+

SenderUsername: senderUsername || undefined,

820+

},

821+

cfg,

822+

commandAuthorized: false,

823+

}).isAuthorizedSender;

824+

}

825+826+

const dmAllow = normalizeDmAllowFromWithStore({

827+

allowFrom: dmAllowFrom,

828+

storeAllowFrom: isGroup ? [] : context.storeAllowFrom,

829+

dmPolicy: context.dmPolicy,

830+

});

831+

const senderAllowed = isSenderAllowed({

832+

allow: dmAllow,

833+

senderId,

834+

senderUsername,

835+

});

836+

const groupSenderAllowed = isGroup

837+

? isSenderAllowed({

838+

allow: context.effectiveGroupAllow,

839+

senderId,

840+

senderUsername,

841+

})

842+

: false;

843+844+

return resolveCommandAuthorizedFromAuthorizers({

845+

useAccessGroups,

846+

authorizers: [

847+

{ configured: dmAllow.hasEntries, allowed: senderAllowed },

848+

...(isGroup

849+

? [

850+

{

851+

configured: context.effectiveGroupAllow.hasEntries,

852+

allowed: groupSenderAllowed,

853+

},

854+

]

855+

: []),

856+

],

857+

modeWhenAccessGroupsOff: "configured",

858+

});

859+

};

860+786861

// Handle emoji reactions to messages.

787862

bot.on("message_reaction", async (ctx) => {

788863

try {

@@ -1453,6 +1528,21 @@ export const registerTelegramHandlers = ({

14531528

// Model selection callback handler (mdl_prov, mdl_list_*, mdl_sel_*, mdl_back)

14541529

const modelCallback = parseModelCallbackData(data);

14551530

if (modelCallback) {

1531+

if (

1532+

!isTelegramModelCallbackAuthorized({

1533+

chatId,

1534+

isGroup,

1535+

senderId,

1536+

senderUsername,

1537+

context: eventAuthContext,

1538+

cfg: runtimeCfg,

1539+

})

1540+

) {

1541+

logVerbose(

1542+

`Blocked telegram model callback from ${senderId || "unknown"} (not authorized for /models)`,

1543+

);

1544+

return;

1545+

}

14561546

let sessionState: ReturnType<typeof resolveTelegramSessionState>;

14571547

let modelData: Awaited<ReturnType<typeof telegramDeps.buildModelsProviderData>>;

14581548

try {