惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
B
Blog
博客园_首页
云风的 BLOG
云风的 BLOG
S
SegmentFault 最新的问题
罗磊的独立博客
Jina AI
Jina AI
C
Check Point Blog
Martin Fowler
Martin Fowler
J
Java Code Geeks
博客园 - 司徒正美
美团技术团队
MongoDB | Blog
MongoDB | Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
大猫的无限游戏
大猫的无限游戏
有赞技术团队
有赞技术团队
U
Unit 42
Hugging Face - Blog
Hugging Face - Blog
WordPress大学
WordPress大学
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - 叶小钗
博客园 - 三生石上(FineUI控件)
小众软件
小众软件

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
fix(cli): preserve optional web fallback secrets · opencl...
steipete · 2026-05-17 · via Recent Commits to openclaw:main

@@ -377,6 +377,45 @@ describe("resolveCommandSecretRefsViaGateway", () => {

377377

}

378378

});

379379380+

it("does not retry old gateways without forced active path support", async () => {

381+

const envKey = "WEB_SEARCH_FIRECRAWL_OLD_GATEWAY_ONLY";

382+

await withEnvValue(envKey, undefined, async () => {

383+

callGateway.mockRejectedValueOnce(

384+

new Error("secrets.resolve invalid request: invalid secrets.resolve params"),

385+

);

386+387+

await expect(

388+

resolveCommandSecretRefsViaGateway({

389+

config: {

390+

tools: {

391+

web: {

392+

search: {

393+

provider: "exa",

394+

},

395+

},

396+

},

397+

plugins: {

398+

entries: {

399+

firecrawl: {

400+

config: {

401+

webSearch: {

402+

apiKey: { source: "env", provider: "default", id: envKey },

403+

},

404+

},

405+

},

406+

},

407+

},

408+

} as unknown as OpenClawConfig,

409+

commandName: "infer web search",

410+

targetIds: new Set(["plugins.entries.firecrawl.config.webSearch.apiKey"]),

411+

allowedPaths: new Set(["plugins.entries.firecrawl.config.webSearch.apiKey"]),

412+

forcedActivePaths: new Set(["plugins.entries.firecrawl.config.webSearch.apiKey"]),

413+

}),

414+

).rejects.toThrow(/does not support command-scoped secret resolution/i);

415+

expect(callGateway).toHaveBeenCalledTimes(1);

416+

});

417+

});

418+380419

it("fails fast when gateway-backed resolution is unavailable", async () => {

381420

const envKey = "TALK_API_KEY_FAILFAST";

382421

const priorValue = process.env[envKey];

@@ -581,6 +620,37 @@ describe("resolveCommandSecretRefsViaGateway", () => {

581620

});

582621

});

583622623+

it("keeps top-level web search SecretRefs on the direct local fallback path", async () => {

624+

const runtimeWebTools = await import("../secrets/runtime-web-tools.js");

625+

vi.mocked(runtimeWebTools.resolveRuntimeWebTools).mockClear();

626+

const envKey = "WEB_SEARCH_BRAVE_TOP_LEVEL_LOCAL_FALLBACK";

627+

await withEnvValue(envKey, "brave-top-level-local-fallback-key", async () => {

628+

callGateway.mockRejectedValueOnce(new Error("gateway closed"));

629+

const result = await resolveCommandSecretRefsViaGateway({

630+

config: {

631+

tools: {

632+

web: {

633+

search: {

634+

provider: "exa",

635+

apiKey: { source: "env", provider: "default", id: envKey },

636+

},

637+

},

638+

},

639+

} as unknown as OpenClawConfig,

640+

commandName: "infer web search",

641+

targetIds: new Set(["tools.web.search.apiKey"]),

642+

forcedActivePaths: new Set(["tools.web.search.apiKey"]),

643+

});

644+645+

expect(result.resolvedConfig.tools?.web?.search?.apiKey).toBe(

646+

"brave-top-level-local-fallback-key",

647+

);

648+

expect(result.targetStatesByPath["tools.web.search.apiKey"]).toBe("resolved_local");

649+

expect(runtimeWebTools.resolveRuntimeWebTools).not.toHaveBeenCalled();

650+

expectGatewayUnavailableLocalFallbackDiagnostics(result);

651+

});

652+

});

653+584654

it("treats command-scoped web fetch fallback SecretRefs as active even when web search is disabled", async () => {

585655

const envKey = "WEB_FETCH_FIRECRAWL_SEARCH_FALLBACK_KEY";

586656

await withEnvValue(envKey, "firecrawl-search-fallback-key", async () => {