惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
J
Java Code Geeks
博客园 - 聂微东
Microsoft Azure Blog
Microsoft Azure Blog
量子位
T
Tailwind CSS Blog
Vercel News
Vercel News
I
InfoQ
Stack Overflow Blog
Stack Overflow Blog
U
Unit 42
Engineering at Meta
Engineering at Meta
L
LangChain Blog
大猫的无限游戏
大猫的无限游戏
D
Docker
博客园_首页
P
Proofpoint News Feed
月光博客
月光博客
T
The Blog of Author Tim Ferriss
MyScale Blog
MyScale Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Martin Fowler
Martin Fowler
腾讯CDC
N
Netflix TechBlog - Medium
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
fix(security): sanitize QQBot debug log values · openclaw...
vincentkoc · 2026-04-30 · via Recent Commits to openclaw:main

File tree

  • extensions/qqbot/src/engine/utils

Original file line numberDiff line numberDiff line change

@@ -42,6 +42,7 @@ Docs: https://docs.openclaw.ai

4242
4343

- Security/outbound: strip re-formed HTML tags during plain-text sanitization so nested tag fragments cannot leave a CodeQL-detected `<script>` sequence behind. Thanks @vincentkoc.

4444

- Security/secrets: compare credential bytes with padded timing-safe buffers instead of hashing candidate passwords before equality checks. Thanks @vincentkoc.

45+

- Security/QQBot: sanitize debug log arguments before writing to `console.*`, so gateway payload fields cannot forge extra log lines when debug logging is enabled. Thanks @vincentkoc.

4546

- CLI/agents/status: keep `openclaw agents`, text `agents list`, and plain text `status` on read-only metadata paths so human output no longer preloads plugin runtimes or live channel scans before printing. Fixes #74195. Thanks @NianJiuZst.

4647

- Agents/local models: derive context-window guard thresholds from the effective model window with 4k/8k safety floors, so small local models are no longer rejected by fixed 16k/32k preflight cutoffs. Fixes #42999. Thanks @chengjialu8888.

4748

- Media: treat legacy Word/OLE attachments with `application/msword` or `application/x-cfb` MIME as binary so printable-looking `.doc` files are not embedded into prompts as text. Fixes #54176; carries forward #54380. Thanks @andyliu.

Original file line numberDiff line numberDiff line change

@@ -0,0 +1,28 @@

1+

import { afterEach, describe, expect, it, vi } from "vitest";

2+

import { debugLog, sanitizeDebugLogValue } from "./log.js";

3+
4+

const originalDebug = process.env.QQBOT_DEBUG;

5+
6+

afterEach(() => {

7+

if (originalDebug === undefined) {

8+

delete process.env.QQBOT_DEBUG;

9+

} else {

10+

process.env.QQBOT_DEBUG = originalDebug;

11+

}

12+

vi.restoreAllMocks();

13+

});

14+
15+

describe("QQBot debug logging", () => {

16+

it("neutralizes control characters in log values", () => {

17+

expect(sanitizeDebugLogValue("before\nforged\r\tentry")).toBe("before forged entry");

18+

});

19+
20+

it("sanitizes arguments before debug console output", () => {

21+

process.env.QQBOT_DEBUG = "1";

22+

const logSpy = vi.spyOn(console, "log").mockImplementation(() => {});

23+
24+

debugLog("prefix", "line one\nline two");

25+
26+

expect(logSpy).toHaveBeenCalledWith("prefix", "line one line two");

27+

});

28+

});

Original file line numberDiff line numberDiff line change

@@ -9,24 +9,53 @@

99

*/

1010
1111

const isDebug = () => !!process.env.QQBOT_DEBUG;

12+

const MAX_LOG_VALUE_CHARS = 4096;

13+
14+

export function sanitizeDebugLogValue(value: unknown): string {

15+

let text: string;

16+

if (typeof value === "string") {

17+

text = value;

18+

} else if (value instanceof Error) {

19+

text = value.stack || value.message;

20+

} else {

21+

try {

22+

text = JSON.stringify(value) ?? String(value);

23+

} catch {

24+

text = String(value);

25+

}

26+

}

27+
28+

const sanitized = text

29+

.replace(/\p{Cc}/gu, " ")

30+

.replace(/\s+/g, " ")

31+

.trim();

32+

if (sanitized.length <= MAX_LOG_VALUE_CHARS) {

33+

return sanitized;

34+

}

35+

return `${sanitized.slice(0, MAX_LOG_VALUE_CHARS)}...`;

36+

}

37+
38+

function sanitizeDebugLogArgs(args: unknown[]): string[] {

39+

return args.map(sanitizeDebugLogValue);

40+

}

1241
1342

/** Debug-level log; only outputs when QQBOT_DEBUG is enabled. */

1443

export function debugLog(...args: unknown[]): void {

1544

if (isDebug()) {

16-

console.log(...args);

45+

console.log(...sanitizeDebugLogArgs(args));

1746

}

1847

}

1948
2049

/** Debug-level warning; only outputs when QQBOT_DEBUG is enabled. */

2150

export function debugWarn(...args: unknown[]): void {

2251

if (isDebug()) {

23-

console.warn(...args);

52+

console.warn(...sanitizeDebugLogArgs(args));

2453

}

2554

}

2655
2756

/** Debug-level error; only outputs when QQBOT_DEBUG is enabled. */

2857

export function debugError(...args: unknown[]): void {

2958

if (isDebug()) {

30-

console.error(...args);

59+

console.error(...sanitizeDebugLogArgs(args));

3160

}

3261

}