惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
The Cloudflare Blog
大猫的无限游戏
大猫的无限游戏
小众软件
小众软件
V
Visual Studio Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 司徒正美
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
酷 壳 – CoolShell
酷 壳 – CoolShell
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
月光博客
月光博客
The GitHub Blog
The GitHub Blog
L
LangChain Blog
D
DataBreaches.Net
T
The Blog of Author Tim Ferriss
F
Fortinet All Blogs
博客园 - Franky
阮一峰的网络日志
阮一峰的网络日志
GbyAI
GbyAI
Apple Machine Learning Research
Apple Machine Learning Research
宝玉的分享
宝玉的分享
Engineering at Meta
Engineering at Meta
V
V2EX
MyScale Blog
MyScale Blog

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
feat(telegram): add real user crabbox proof · openclaw/op...
obviyus · 2026-05-10 · via Recent Commits to openclaw:main

@@ -404,6 +404,9 @@ Default endpoint contract (`OPENCLAW_QA_CONVEX_SITE_URL` + `/qa-credentials/v1`)

404404

- Request: `{ kind, ownerId, actorRole, leaseTtlMs, heartbeatIntervalMs }`

405405

- Success: `{ status: "ok", credentialId, leaseToken, payload, leaseTtlMs?, heartbeatIntervalMs? }`

406406

- Exhausted/retryable: `{ status: "error", code: "POOL_EXHAUSTED" | "NO_CREDENTIAL_AVAILABLE", ... }`

407+

- `POST /payload-chunk`

408+

- Request: `{ kind, ownerId, actorRole, credentialId, leaseToken, index }`

409+

- Success: `{ status: "ok", index, data }`

407410

- `POST /heartbeat`

408411

- Request: `{ kind, ownerId, actorRole, credentialId, leaseToken, leaseTtlMs }`

409412

- Success: `{ status: "ok" }` (or empty `2xx`)

@@ -427,6 +430,46 @@ Payload shape for Telegram kind:

427430

- `groupId` must be a numeric Telegram chat id string.

428431

- `admin/add` validates this shape for `kind: "telegram"` and rejects malformed payloads.

429432433+

Payload shape for Telegram real-user kind:

434+435+

- `{ groupId: string, sutToken: string, testerUserId: string, testerUsername: string, telegramApiId: string, telegramApiHash: string, tdlibDatabaseEncryptionKey: string, tdlibArchiveBase64: string, tdlibArchiveSha256: string, desktopTdataArchiveBase64: string, desktopTdataArchiveSha256: string }`

436+

- `groupId`, `testerUserId`, and `telegramApiId` must be numeric strings.

437+

- `tdlibArchiveSha256` and `desktopTdataArchiveSha256` must be SHA-256 hex strings.

438+

- `kind: "telegram-user"` represents one Telegram burner account. Treat the lease as account-wide: the TDLib CLI driver and Telegram Desktop visual witness restore from the same payload, and only one job should hold the lease at a time.

439+440+

Telegram real-user lease restore:

441+442+

```bash

443+

tmp=$(mktemp -d /tmp/openclaw-telegram-user.XXXXXX)

444+

node --import tsx scripts/e2e/telegram-user-credential.ts lease-restore \

445+

--user-driver-dir "$tmp/user-driver" \

446+

--desktop-workdir "$tmp/desktop" \

447+

--lease-file "$tmp/lease.json"

448+

TELEGRAM_USER_DRIVER_STATE_DIR="$tmp/user-driver" \

449+

uv run ~/.codex/skills/custom/telegram-e2e-bot-to-bot/scripts/user-driver.py status --json

450+

node --import tsx scripts/e2e/telegram-user-credential.ts release --lease-file "$tmp/lease.json"

451+

```

452+453+

Use the restored Desktop profile with `Telegram -workdir "$tmp/desktop"` when a visual recording is needed. In local operator environments, `scripts/e2e/telegram-user-credential.ts` reads `~/.codex/skills/custom/telegram-e2e-bot-to-bot/convex.local.env` by default if process env vars are absent.

454+455+

One-command Crabbox proof:

456+457+

```bash

458+

pnpm qa:telegram-user:crabbox -- --text /status

459+

```

460+461+

That command leases the `telegram-user` credential, restores the same account

462+

into TDLib and Telegram Desktop on a Crabbox Linux desktop, starts a local mock

463+

SUT gateway from the current checkout, sends the command as the real QA user,

464+

records the visible Telegram Desktop session, trims the recording to the motion

465+

window, writes artifacts under `.artifacts/qa-e2e/telegram-user-crabbox/`, then

466+

releases the credential and stops the box. Use `--id <cbx_...>` to reuse a warm

467+

desktop lease, `--keep-box` to keep VNC open after failure,

468+

`--desktop-chat-title <name>` to pick the visible chat, and `--tdlib-url <tgz>`

469+

when using a prebaked Linux `libtdjson.so` archive instead of building TDLib on

470+

a fresh box. The runner verifies `--tdlib-url` with `--tdlib-sha256 <hex>` or,

471+

by default, a sibling `<url>.sha256` file.

472+430473

Broker-validated multi-channel payloads:

431474432475

- Discord: `{ guildId: string, channelId: string, driverBotToken: string, sutBotToken: string, sutApplicationId: string, voiceChannelId?: string }`