mirror of
https://github.com/openclaw/openclaw.git
synced 2026-07-28 12:51:11 +00:00
Adds client-capability-gated tool availability: gateway clients declare capabilities at connect (new inline-widgets cap), chat.send stamps them into the run context, and every tool assembly path (embedded runner, queued followups, Codex app-server harness, plugin-only construction plans) drops tools whose requiredClientCaps the originating client did not declare. The Canvas plugin ships the first such tool, show_widget: agents pass SVG or an HTML fragment plus a title; the plugin hosts it as a bounded, retention-scoped Canvas document and returns the existing canvas preview handle, which web chat renders as a sandboxed iframe fitted to the widget's reported content height. Widget frames never get allow-same-origin (per-preview sandbox ceiling, including the sidebar path) and the Canvas host serves widget documents with a CSP sandbox header so direct navigation runs in an opaque origin. Verified live end-to-end on a Testbox with gpt-5.5 (screenshots on the PR). CLI-backed model backends do not carry client caps yet and stay fail-closed (#102577). Closes #101790
17 lines
658 B
TypeScript
17 lines
658 B
TypeScript
// @vitest-environment node
|
|
|
|
import { describe, expect, it } from "vitest";
|
|
import { resolveEmbedSandbox } from "./tool-display.ts";
|
|
|
|
describe("resolveEmbedSandbox", () => {
|
|
it("caps a trusted global sandbox at scripts-only for isolated previews", () => {
|
|
expect(resolveEmbedSandbox("trusted", "scripts")).toBe("allow-scripts");
|
|
expect(resolveEmbedSandbox("scripts", "scripts")).toBe("allow-scripts");
|
|
expect(resolveEmbedSandbox("strict", "scripts")).toBe("");
|
|
});
|
|
|
|
it("preserves existing behavior when a preview has no sandbox ceiling", () => {
|
|
expect(resolveEmbedSandbox("trusted")).toBe("allow-scripts allow-same-origin");
|
|
});
|
|
});
|