Patrick Erichsen
e9671ed603
feat: feature openrouter in onboarding provider picker
2026-06-09 21:59:56 -07:00
kenny
b9280d5863
feat: add OpenRouter OAuth login
...
(cherry picked from commit dccfb60656 )
2026-06-09 21:59:56 -07:00
Vincent Koc
b4cdd92119
fix(codex): avoid guardian review for local models ( #88630 )
...
* fix(codex): avoid guardian review for local models
* fix(codex): route app-server auto exec review
* fix(codex): make guardian requirements provider-aware
* fix(codex): block unrouted bound approvals
* fix(channels): satisfy ingress queue lint
* fix(codex): use local-model policy for side forks
* fix(extensions): satisfy ingress lint
* fix(codex): require trusted exec reviewer model
* fix(exec): share control command approval guards
* fix(codex): fail closed for unknown guardian model provider
* fix(codex): reject custom exec reviewer endpoints
* fix(codex): preserve bound providers on app-server reuse
* fix(codex): prefer qualified app-server model providers
* fix(codex): preserve guardian on model control switches
* fix(codex): retain local providers across model switches
* fix(codex): distrust aliased reviewer model refs
* fix(codex): preserve providers after thread rotation
* fix(codex): clear stale providers on qualified model switches
* fix(codex): prefer qualified models over legacy providers
* fix(codex): validate reviewer trust before auto approvals
* fix(codex): recompute reviewer policy after binding rotation
* fix(codex): normalize reviewer aliases before trust checks
* fix(codex): retain bound providers for slashed local models
* fix(codex): normalize provider trust checks for exec review
* fix(codex): ignore stale bindings for explicit providers
* fix(codex): share trusted reviewer endpoint policy
* fix(codex): keep network approvals on plugin path
* fix(codex): route provider-qualified model refs
* fix(codex): reject blank masked OpenAI base overrides
* fix(codex): scope exec reviewer alias trust
* fix(codex): distrust exec reviewer transport overrides
2026-06-09 21:38:22 -07:00
Patrick Erichsen
5a0b95269d
docs: add plugin validation fixes guide ( #91819 )
2026-06-09 21:14:17 -07:00
dependabot[bot]
69b95c3447
chore(deps): bump useblacksmith/setup-docker-builder ( #91666 )
...
Bumps the actions group with 1 update: [useblacksmith/setup-docker-builder](https://github.com/useblacksmith/setup-docker-builder ).
Updates `useblacksmith/setup-docker-builder` from 1.8.0 to 1.9.0
- [Release notes](https://github.com/useblacksmith/setup-docker-builder/releases )
- [Commits](722e97d12b...ab5c1da94f )
---
updated-dependencies:
- dependency-name: useblacksmith/setup-docker-builder
dependency-version: 1.9.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-09 20:57:06 -07:00
Colin Johnson
bf89552e67
Improve iPad and iPhone control surfaces ( #91557 )
...
* feat(ios): expand iPad layout support
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
* feat: improve iPad and iPhone control surfaces
* fix: preserve workboard dispatch compatibility
* fix: keep Talk reachable on iPad
* fix: add universal iPad app icons
* fix: address ready-review iOS feedback
* fix: avoid workboard board id shadowing
* fix ios sidebar separators
---------
Co-authored-by: Solvely-Colin <211764741+Solvely-Colin@users.noreply.github.com >
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Co-authored-by: joshavant <830519+joshavant@users.noreply.github.com >
2026-06-09 21:46:02 -05:00
Josh Avant
a8d33f23a0
Fix context-engine compaction ownership for Codex sessions ( #91590 )
...
* fix(agents): keep context-engine compaction primary
* fix(codex): request native compaction after context engines
* test: cover 90496 compaction and reset edge cases
* fix(codex): guard secondary native compaction binding
* fix(codex): keep native compaction hint internal
* fix(codex): wait for active native turns before resume
2026-06-09 21:33:00 -05:00
Omar Shahine
6c045c5ca3
fix(imessage): surface inbound startup diagnostics ( #91785 )
...
Merged via squash.
Prepared head SHA: 597684c365
Proof:
- Focused tests, lint/type/diff checks, and autoreview passed before merge.
- ClawSweeper re-review marked proof and patch quality platinum after lobster live monitor proof.
- Maintainer accepted the diagnostics-only default-log privacy/noise tradeoff.
Lobster proof id: openclaw-lobster-live-monitor-proof-ada22165-6306-46b6-8ed0-6c94fcab6bbc
Reviewed-by: @omarshahine
2026-06-09 19:10:09 -07:00
Omar Shahine
bfccbc3fee
fix(imessage): harden outbound send transport ( #91783 )
...
Merged via squash.
Prepared head SHA: 39ea25767b
Proof:
- Focused tests, docs/config generation, lint/type/doc checks passed before merge.
- ClawSweeper re-review marked proof and patch quality platinum after lobster live send proof.
- Maintainer accepted the `channels.imessage.sendTransport` config surface and compatibility-risk tradeoff.
Lobster proof id: openclaw-lobster-live-proof-c74895c2-b629-4bb0-abcb-e6521069b3d8
Reviewed-by: @omarshahine
2026-06-09 19:09:15 -07:00
Vincent Koc
9a1f2022b1
fix(security): avoid crypto hash for oauth lock names
2026-06-10 09:54:38 +09:00
Vincent Koc
5967ae61bd
fix(security): audit oauth lock hash
2026-06-10 09:32:32 +09:00
Vincent Koc
48ec58a584
fix(security): remediate openclaw alerts
2026-06-10 09:02:00 +09:00
openclaw-clownfish[bot]
c0a4a7890d
fix(doctor): keep TTS legacy migration on supported paths ( #91787 )
...
Co-authored-by: openclaw-clownfish[bot] <280122609+openclaw-clownfish[bot]@users.noreply.github.com>
2026-06-10 08:54:36 +09:00
Vincent Koc
0a6a10193d
fix(release): guard Parallels skip-restore lanes
2026-06-10 08:27:59 +09:00
Vincent Koc
c350c35fad
fix(release): allow QA capability restore patch
...
(cherry picked from commit db711701d2 )
2026-06-10 08:27:59 +09:00
Vincent Koc
56dc53f6d2
fix(release): harden Parallels smoke validation
...
(cherry picked from commit 810a821c65 )
2026-06-10 08:27:59 +09:00
Dallin Romney
ec0f311f7f
fix(config): clarify retired skill workshop plugin warning ( #91757 )
2026-06-09 16:26:02 -07:00
Agustin Rivera
f0d8048aa3
fix(search): enforce native web search tool policy ( #91750 )
...
* fix(search): enforce native web search tool policy
* fix(search): apply session policy to native web search
* fix(search): gate direct OpenAI native search
* fix(search): redact native web search provider context
2026-06-09 16:25:15 -07:00
openclaw-clownfish[bot]
54415d322f
fix(ui): drain restored chat queue after session switch ( #91780 )
...
Co-authored-by: openclaw-clownfish[bot] <280122609+openclaw-clownfish[bot]@users.noreply.github.com>
Co-authored-by: tmimmanuel <14046872+tmimmanuel@users.noreply.github.com >
2026-06-10 08:20:12 +09:00
colmbrogan
3a9ea1d85b
fix(imessage): skip idle approval discovery scans ( #88530 )
...
* fix(imessage): bound idle approval discovery scans
* fix(imessage): complete bounded approval discovery
---------
Co-authored-by: Omar Shahine <10343873+omarshahine@users.noreply.github.com >
2026-06-09 16:03:48 -07:00
Michael Appel
a90eb93452
Harden sandbox bind source validation ( #91741 )
2026-06-09 15:59:03 -07:00
clawsweeper[bot]
468db12c21
fix(mcp): lowercase SSE event-source header keys to prevent duplicate Authorization (401) ( #91773 )
...
Summary:
- The branch lowercases SSE EventSource SDK and operator header keys before merging and adds a regression test for duplicate case-variant Authorization headers.
- PR surface: Source 0, Tests +59. Total +59 across 2 files.
- Reproducibility: yes. Source inspection shows current main can preserve both lowercase `authorization` from ... K EventSource hook and configured `Authorization`, and the PR adds a focused regression test for that path.
Automerge notes:
- PR branch already contained follow-up commit before automerge: fix(mcp): lowercase SSE event-source header keys to prevent duplicate…
Validation:
- ClawSweeper review passed for head c8f7a7940e .
- Required merge gates passed before the squash merge.
Prepared head SHA: c8f7a7940e
Review: https://github.com/openclaw/openclaw/pull/91773#issuecomment-4664644390
Co-authored-by: clawsweeper <274271284+clawsweeper[bot]@users.noreply.github.com>
Co-authored-by: clawsweeper[bot] <274271284+clawsweeper[bot]@users.noreply.github.com>
Approved-by: takhoffman
Co-authored-by: takhoffman <781889+takhoffman@users.noreply.github.com >
2026-06-09 22:52:29 +00:00
Patrick Erichsen
4ca6ac326e
docs: remove superpowers spec draft
2026-06-09 15:51:37 -07:00
Andy Ye
9833f3ea9b
fix(ui): require user intent for chat sessions ( #91480 )
...
Summary:
- The PR adds an explicit user-intent argument to `createChatSession`, updates the New Chat and `/new` action callers to pass it, adds helper regression coverage, and carries minor gateway formatting/import ordering churn.
- PR surface: Source +8, Tests +9. Total +17 across 8 files.
- Reproducibility: yes. at source level: current main lets `createChatSession(state)` reach `sessions.create` ... ct flow, so the exact user-path reproduction remains integration-level rather than locally reproduced here.
Automerge notes:
- PR branch already contained follow-up commit before automerge: test(tasks): restore timers before maintenance apply
- PR branch already contained follow-up commit before automerge: Merge remote-tracking branch 'origin/main' into HEAD
Validation:
- ClawSweeper review passed for head e7cd79006b .
- Required merge gates passed before the squash merge.
Prepared head SHA: e7cd79006b
Review: https://github.com/openclaw/openclaw/pull/91480#issuecomment-4651778423
Co-authored-by: Andy Ye <35905412+TurboTheTurtle@users.noreply.github.com >
Co-authored-by: clawsweeper[bot] <274271284+clawsweeper[bot]@users.noreply.github.com>
Approved-by: takhoffman
Co-authored-by: takhoffman <781889+takhoffman@users.noreply.github.com >
2026-06-09 22:40:07 +00:00
Jacob Tomlinson
e9bd90d209
docs(security): clarify env var report scope ( #91765 )
2026-06-10 06:14:24 +09:00
Agustin Rivera
314de694c4
fix(mcp): harden stdio env filtering ( #91751 )
2026-06-09 14:08:47 -07:00
Shakker
4648701fc1
chore: fix ACP guard lint issues
2026-06-09 22:07:05 +01:00
Shakker
3b7631e50d
perf: bound ACP metadata key repair lookup
2026-06-09 22:07:05 +01:00
Shakker
21104cd52e
test: use valid deleted ACP bridge fixture
2026-06-09 22:07:05 +01:00
Shakker
6ab084e89d
test: use valid configured ACP bridge fixture
2026-06-09 22:07:05 +01:00
Shakker
e16193bad5
fix: skip ACP metadata probe for configured agents
2026-06-09 22:07:05 +01:00
Shakker
31d49c59d7
test: require ACP metadata in resolve unit fixture
2026-06-09 22:07:05 +01:00
Shakker
ef2ca9e50e
fix: repair ACP metadata in deleted-agent guard
2026-06-09 22:07:05 +01:00
Shakker
09854d9de7
fix: make ACP metadata key repair idempotent
2026-06-09 22:07:05 +01:00
Shakker
d31d26ef42
fix: validate migrated ACP metadata at canonical key
2026-06-09 22:07:05 +01:00
Shakker
440284f879
fix: rekey ACP metadata during session key migration
2026-06-09 22:07:05 +01:00
Shakker
784e86433c
fix: preserve ACP metadata key during deleted-agent checks
2026-06-09 22:07:05 +01:00
Shakker
a82abc771a
fix: align session resolve deleted-agent entry type
2026-06-09 22:07:05 +01:00
Shakker
a93bc61a84
fix: read canonical ACP metadata for deleted-agent guard
2026-06-09 22:07:05 +01:00
Shakker
b502a92bf1
fix: require ACP metadata for deleted-agent bypass
2026-06-09 22:07:05 +01:00
Agustin Rivera
21410d1c32
fix(codex): guard sandbox http requests ( #91752 )
...
* fix(codex): guard sandbox http requests
* fix(codex): align sandbox http policy
2026-06-09 13:54:24 -07:00
Agustin Rivera
a4e02cd1dd
fix(elevated): reject group ids as senders ( #91748 )
...
* fix(elevated): reject group ids as senders
* fix(elevated): keep channel parsing out of core
2026-06-09 13:20:36 -07:00
Agustin Rivera
b6a3f2988c
fix(gateway): restrict non-owner loopback tools ( #91749 )
...
* fix(gateway): restrict non-owner loopback tools
* fix(gateway): split loopback owner cache key
2026-06-09 13:15:48 -07:00
Alex Knight
bf95883812
feat(diagnostics-otel): capture tool input/output content via trusted channel ( #91256 )
...
diagnostics.otel.captureContent.{toolInputs,toolOutputs} were documented
and config-wired but never produced any span content. Emit tool args and
results over the trusted private-data diagnostic channel (mirroring the
model-content path), and have the OTel exporter bound/redact/truncate them
before span export. Raw tool content never rides the public event bus.
Scope: core embedded-runner tool path (canonical producer). Codex
(async-batched) and Claude CLI remain follow-ups tracked by the issue.
Refs #77391
2026-06-10 05:52:52 +10:00
Agustin Rivera
d2ddc26e89
fix(msteams): require admin for group actions ( #91746 )
2026-06-09 12:52:24 -07:00
Niels Kaspers
96a49caffa
docs: clarify trusted-proxy websocket scopes ( #85950 )
2026-06-09 12:40:12 -07:00
Agustin Rivera
2649064548
fix(discord): require sender for moderation actions ( #91745 )
2026-06-09 12:33:38 -07:00
Dallin Romney
370cef2e3b
docs: align Feishu DM policy defaults ( #91755 )
2026-06-09 12:31:47 -07:00
Dallin Romney
a2dd821908
docs: clarify matrix plugin upgrade repair ( #91753 )
2026-06-09 12:22:59 -07:00
Shubhankar Tripathy
443115c632
fix(config): warn for retired skill-workshop plugin entry instead of failing validation ( #90244 ) ( #90838 )
2026-06-09 12:20:34 -07:00