惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园_首页
雷峰网
雷峰网
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
WordPress大学
WordPress大学
腾讯CDC
T
Tailwind CSS Blog
A
About on SuperTechFans
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The GitHub Blog
The GitHub Blog
T
The Blog of Author Tim Ferriss
G
Google Developers Blog
The Cloudflare Blog
D
DataBreaches.Net
Recent Announcements
Recent Announcements
Engineering at Meta
Engineering at Meta
B
Blog
博客园 - 聂微东
阮一峰的网络日志
阮一峰的网络日志
月光博客
月光博客
博客园 - 司徒正美
MongoDB | Blog
MongoDB | Blog
Google DeepMind News
Google DeepMind News
Apple Machine Learning Research
Apple Machine Learning Research

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
fix: thread workspace auth evidence through model auth · ...
shakkernerd · 2026-04-30 · via Recent Commits to openclaw:main

@@ -52,8 +52,9 @@ const log = createSubsystemLogger("model-auth");

5252

function resolveConfigAwareEnvApiKey(

5353

cfg: OpenClawConfig | undefined,

5454

provider: string,

55+

workspaceDir?: string,

5556

): EnvApiKeyResult | null {

56-

return resolveEnvApiKey(provider, process.env, { config: cfg });

57+

return resolveEnvApiKey(provider, process.env, { config: cfg, workspaceDir });

5758

}

58595960

function resolveProviderConfig(

@@ -315,14 +316,20 @@ export function hasSyntheticLocalProviderAuthConfig(params: {

315316

export function hasRuntimeAvailableProviderAuth(params: {

316317

provider: string;

317318

cfg?: OpenClawConfig;

319+

workspaceDir?: string;

318320

env?: NodeJS.ProcessEnv;

319321

}): boolean {

320322

const provider = normalizeProviderId(params.provider);

321323

const authOverride = resolveProviderAuthOverride(params.cfg, provider);

322324

if (authOverride === "aws-sdk") {

323325

return true;

324326

}

325-

if (resolveEnvApiKey(provider, params.env)) {

327+

if (

328+

resolveEnvApiKey(provider, params.env, {

329+

config: params.cfg,

330+

workspaceDir: params.workspaceDir,

331+

})

332+

) {

326333

return true;

327334

}

328335

if (resolveUsableCustomProviderApiKey({ cfg: params.cfg, provider, env: params.env })) {

@@ -489,6 +496,7 @@ export async function resolveApiKeyForProvider(params: {

489496

preferredProfile?: string;

490497

store?: AuthProfileStore;

491498

agentDir?: string;

499+

workspaceDir?: string;

492500

/** When true, treat profileId as a user-locked selection that must not be

493501

* silently overridden by env/config credentials. */

494502

lockedProfile?: boolean;

@@ -553,7 +561,7 @@ export async function resolveApiKeyForProvider(params: {

553561

}

554562555563

if (params.credentialPrecedence === "env-first") {

556-

const envResolved = resolveConfigAwareEnvApiKey(cfg, provider);

564+

const envResolved = resolveConfigAwareEnvApiKey(cfg, provider, params.workspaceDir);

557565

if (envResolved) {

558566

const resolvedMode: ResolvedProviderAuth["mode"] = envResolved.source.includes("OAUTH_TOKEN")

559567

? "oauth"

@@ -575,7 +583,7 @@ export async function resolveApiKeyForProvider(params: {

575583

mode: "api-key",

576584

};

577585

}

578-

const localMarkerEnv = resolveConfigAwareEnvApiKey(cfg, provider);

586+

const localMarkerEnv = resolveConfigAwareEnvApiKey(cfg, provider, params.workspaceDir);

579587

if (localMarkerEnv && isNonSecretApiKeyMarker(localMarkerEnv.apiKey)) {

580588

return {

581589

apiKey: localMarkerEnv.apiKey,

@@ -626,7 +634,7 @@ export async function resolveApiKeyForProvider(params: {

626634

}

627635

}

628636629-

const envResolved = resolveConfigAwareEnvApiKey(cfg, provider);

637+

const envResolved = resolveConfigAwareEnvApiKey(cfg, provider, params.workspaceDir);

630638

if (envResolved) {

631639

const resolvedMode: ResolvedProviderAuth["mode"] = envResolved.source.includes("OAUTH_TOKEN")

632640

? "oauth"

@@ -699,6 +707,7 @@ export function resolveModelAuthMode(

699707

provider?: string,

700708

cfg?: OpenClawConfig,

701709

store?: AuthProfileStore,

710+

options?: { workspaceDir?: string },

702711

): ModelAuthMode | undefined {

703712

const resolved = provider?.trim();

704713

if (!resolved) {

@@ -739,7 +748,7 @@ export function resolveModelAuthMode(

739748

return "aws-sdk";

740749

}

741750742-

const envKey = resolveConfigAwareEnvApiKey(cfg, resolved);

751+

const envKey = resolveConfigAwareEnvApiKey(cfg, resolved, options?.workspaceDir);

743752

if (envKey?.apiKey) {

744753

return envKey.source.includes("OAUTH_TOKEN") ? "oauth" : "api-key";

745754

}

@@ -764,14 +773,15 @@ export async function hasAvailableAuthForProvider(params: {

764773

preferredProfile?: string;

765774

store?: AuthProfileStore;

766775

agentDir?: string;

776+

workspaceDir?: string;

767777

}): Promise<boolean> {

768778

const { provider, cfg, preferredProfile } = params;

769779770780

const authOverride = resolveProviderAuthOverride(cfg, provider);

771781

if (authOverride === "aws-sdk") {

772782

return true;

773783

}

774-

if (resolveConfigAwareEnvApiKey(cfg, provider)) {

784+

if (resolveConfigAwareEnvApiKey(cfg, provider, params.workspaceDir)) {

775785

return true;

776786

}

777787

if (resolveUsableCustomProviderApiKey({ cfg, provider })) {

@@ -816,6 +826,7 @@ export async function getApiKeyForModel(params: {

816826

preferredProfile?: string;

817827

store?: AuthProfileStore;

818828

agentDir?: string;

829+

workspaceDir?: string;

819830

lockedProfile?: boolean;

820831

credentialPrecedence?: ProviderCredentialPrecedence;

821832

}): Promise<ResolvedProviderAuth> {

@@ -826,6 +837,7 @@ export async function getApiKeyForModel(params: {

826837

preferredProfile: params.preferredProfile,

827838

store: params.store,

828839

agentDir: params.agentDir,

840+

workspaceDir: params.workspaceDir,

829841

lockedProfile: params.lockedProfile,

830842

credentialPrecedence: params.credentialPrecedence,

831843

});