惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

N
Netflix TechBlog - Medium
IT之家
IT之家
博客园_首页
Hugging Face - Blog
Hugging Face - Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
美团技术团队
小众软件
小众软件
博客园 - 叶小钗
WordPress大学
WordPress大学
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 三生石上(FineUI控件)
罗磊的独立博客
博客园 - Franky
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Last Week in AI
Last Week in AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
有赞技术团队
有赞技术团队
T
Tailwind CSS Blog
宝玉的分享
宝玉的分享
博客园 - 【当耐特】
月光博客
月光博客
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
酷 壳 – CoolShell
酷 壳 – CoolShell
人人都是产品经理
人人都是产品经理

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
fix(ui): polish assistant identity settings · openclaw/op...
BunsDev · 2026-04-25 · via Recent Commits to openclaw:main

@@ -3,8 +3,10 @@ import path from "node:path";

33

import type { OpenClawConfig } from "../config/types.openclaw.js";

44

import {

55

AVATAR_MAX_BYTES,

6+

hasAvatarUriScheme,

67

isAvatarDataUrl,

78

isAvatarHttpUrl,

9+

isWindowsAbsolutePath,

810

isPathWithinRoot,

911

isSupportedLocalAvatarExtension,

1012

} from "../shared/avatar-policy.js";

@@ -15,10 +17,18 @@ import { loadAgentIdentityFromWorkspace } from "./identity-file.js";

1517

import { resolveAgentIdentity } from "./identity.js";

16181719

export type AgentAvatarResolution =

18-

| { kind: "none"; reason: string }

19-

| { kind: "local"; filePath: string }

20-

| { kind: "remote"; url: string }

21-

| { kind: "data"; url: string };

20+

| { kind: "none"; reason: string; source?: string }

21+

| { kind: "local"; filePath: string; source: string }

22+

| { kind: "remote"; url: string; source: string }

23+

| { kind: "data"; url: string; source: string };

24+25+

type AgentAvatarPublicSourceInput = {

26+

kind: AgentAvatarResolution["kind"];

27+

source?: string | null;

28+

};

29+30+

const PUBLIC_AVATAR_SOURCE_MAX_CHARS = 256;

31+

const PUBLIC_DATA_AVATAR_HEADER_MAX_CHARS = 64;

22322333

function resolveAvatarSource(

2434

cfg: OpenClawConfig,

@@ -80,6 +90,42 @@ function resolveLocalAvatarPath(params: {

8090

return { ok: true, filePath: realPath };

8191

}

829293+

function isSafeRelativeAvatarSource(source: string): boolean {

94+

if (

95+

source.length > PUBLIC_AVATAR_SOURCE_MAX_CHARS ||

96+

source.startsWith("~") ||

97+

path.isAbsolute(source) ||

98+

isWindowsAbsolutePath(source) ||

99+

(hasAvatarUriScheme(source) && !isWindowsAbsolutePath(source)) ||

100+

source.includes("\0")

101+

) {

102+

return false;

103+

}

104+

const parts = source.replace(/\\/g, "/").split("/");

105+

return parts.every((part) => part !== "..");

106+

}

107+108+

export function resolvePublicAgentAvatarSource(

109+

resolved: AgentAvatarPublicSourceInput,

110+

): string | undefined {

111+

const source = normalizeOptionalString(resolved.source) ?? null;

112+

if (!source) {

113+

return undefined;

114+

}

115+

if (isAvatarDataUrl(source)) {

116+

const commaIndex = source.indexOf(",");

117+

const header =

118+

commaIndex > 0

119+

? source.slice(0, Math.min(commaIndex, PUBLIC_DATA_AVATAR_HEADER_MAX_CHARS))

120+

: source.slice(0, PUBLIC_DATA_AVATAR_HEADER_MAX_CHARS);

121+

return `${header},...`;

122+

}

123+

if (isAvatarHttpUrl(source)) {

124+

return "remote URL";

125+

}

126+

return isSafeRelativeAvatarSource(source) ? source : undefined;

127+

}

128+83129

export function resolveAgentAvatar(

84130

cfg: OpenClawConfig,

85131

agentId: string,

@@ -90,15 +136,15 @@ export function resolveAgentAvatar(

90136

return { kind: "none", reason: "missing" };

91137

}

92138

if (isAvatarHttpUrl(source)) {

93-

return { kind: "remote", url: source };

139+

return { kind: "remote", url: source, source };

94140

}

95141

if (isAvatarDataUrl(source)) {

96-

return { kind: "data", url: source };

142+

return { kind: "data", url: source, source };

97143

}

98144

const workspaceDir = resolveAgentWorkspaceDir(cfg, agentId);

99145

const resolved = resolveLocalAvatarPath({ raw: source, workspaceDir });

100146

if (!resolved.ok) {

101-

return { kind: "none", reason: resolved.reason };

147+

return { kind: "none", reason: resolved.reason, source };

102148

}

103-

return { kind: "local", filePath: resolved.filePath };

149+

return { kind: "local", filePath: resolved.filePath, source };

104150

}